CVE-2008-0720 describes a Cross-site Scripting (XSS) vulnerability affecting Webmin versions 1.370 and 1.390, and Usermin versions 1.300 and 1.320. This flaw allows remote attackers to inject arbitrary web script or HTML, primarily through the 'search' parameter in webmin_search.cgi or similar search/open file boxes. The vulnerability has a CVSS v2 base score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and leading to partial integrity impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:webmin:usermin:1.3:*:*:*:*:*:*:* | ||
1.32CPE matchmatch criteria | cpe:2.3:a:webmin:usermin:1.32:*:*:*:*:*:*:* | ||
1.370CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:1.370:*:*:*:*:*:*:* | ||
1.390CPE matchmatch criteria | cpe:2.3:a:webmin:webmin:1.390:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.