Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.
| Software | From | Fixed in |
|---|---|---|
| webmin / webmin | - | 1.680.x |
| webmin / userwin | - | 1.590.x |