CVE-2014-3884

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
20/07/2014
Last modified:
12/04/2025

Description

Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webmin:usermin:*:*:*:*:*:*:*:* 1.590 (including)
cpe:2.3:a:webmin:usermin:0.4:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.5:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.6:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.7:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.80:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.90:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.910:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.929:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.930:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.940:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.950:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.960:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.970:*:*:*:*:*:*:*
cpe:2.3:a:webmin:usermin:0.980:*:*:*:*:*:*:*