A Stored Cross-Site Scripting (XSS) vulnerability in the MIME type programs tab in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML via the description field while creating a new MIME type program.
| Software | From | Fixed in |
|---|---|---|
| webmin / usermin | 2.000 | 2.000.x |