A Stored Cross-Site Scripting (XSS) vulnerability in the Account Plans tab of System Settings in Virtualmin 7.7 allows remote attackers to inject arbitrary web script or HTML via the Plan name field while editing Account plan details.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-31T00:00:00

Updated: 2023-11-01T21:46:27.191019

Reserved: 2023-10-30T00:00:00


Link: CVE-2023-47094

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-01T00:15:09.380

Modified: 2023-11-06T17:59:03.860


Link: CVE-2023-47094

JSON object: View

cve-icon Redhat Information

No data.

CWE