Logo
vulnerabilityCVE-2020-12670
Name
CVE-2020-12670
Source
NVD ( link)Debian ( link)
Description
XSS exists in Webmin 1.941 and earlier affecting the Save function of the Read User Email Module / mailboxes Endpoint when attempting to save HTML emails. This module parses any output without sanitizing SCRIPT elements, as opposed to the View function, which sanitizes the input correctly. A malicious user can send any JavaScript payload into the message body and execute it if the user decides to save that email.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
webmin
Exploitable

Vulnerability Ratings#


6.1
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
1.850
Exploitable
yocto
master
2.641
Not Affected