4.3
CVSSv2

CVE-2022-36880

Published: 27/07/2022 Updated: 02/08/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Read Mail module in Webmin 1.995 and Usermin up to and including 1.850 allows XSS via a crafted HTML e-mail message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webmin usermin

webmin webmin 1.995

Github Repositories

Vulnerabilities for webmin 1.995 and usermin 1.850

Usermin Vulnerabilities for usermin 1850 and prior Code Execution 1 - CVE-2022-35132 Type: Authenticated code execution A authenticated user can execute commands using the GPG module This is useful if the shell module has been restricted for that user Vulnerability: importcgi line 24 executes unsanitized user input $out = `$gpgpath --import '$in{'file'}