A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field.
References
Link Resource
http://webmin.com Product
https://github.com/Vi39/Webmin-2.100/blob/main/CVE-2023-40986 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-09-15T00:00:00

Updated: 2023-09-15T00:23:09.645281

Reserved: 2023-08-22T00:00:00


Link: CVE-2023-40986

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-15T01:15:07.910

Modified: 2023-09-20T13:11:09.520


Link: CVE-2023-40986

JSON object: View

cve-icon Redhat Information

No data.

CWE