
Cloud Vulnerability DB
A community-led vulnerabilities database
The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows Cross-Site Scripting (XSS) via a crafted HTML e-mail message (Webmin Security, CVE Mitre). The vulnerability was discovered and disclosed in June 2022.
The vulnerability exists in the Read Mail module's handling of HTML email messages. When a maliciously crafted HTML email is opened, it can execute arbitrary web scripts within the context of the user's browser, potentially leading to the capture of browser cookies (Webmin Security).
If successfully exploited, the vulnerability could allow attackers to execute arbitrary scripts in the victim's browser when opening a crafted HTML email. This could lead to session hijacking through cookie theft and potentially compromise the user's Webmin session (Webmin Security).
The vulnerability has been patched in versions after Webmin 1.995 and Usermin 1.850. Users should upgrade to the latest version to protect against this vulnerability. The fix addresses the HTML handling in the Read Mail module to prevent execution of malicious scripts (Webmin Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."