The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ly1g3/webmin-usermin-vulnerabilities