CVE-2023-41163

MEDIUM

Usermin 2.000 - XSS

Title source: llm
STIX 2.1

Description

A Reflected Cross-site scripting (XSS) vulnerability in the file manager tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the replace in results field while replacing the results under the tools drop down.

Scores

CVSS v3 6.1
EPSS 0.0008
EPSS Percentile 23.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
webmin/webmin 2.000
Published Aug 30, 2023
Tracked Since Feb 18, 2026