A Stored Cross-Site Scripting (XSS) vulnerability while editing the autoreply file page in Usermin 2.000 allows remote attackers to inject arbitrary web script or HTML by editing the forward file manually.
https://webmin.com/tags/webmin-changelog/
https://github.com/shindeanik/Usermin-2.000/blob/main/CVE-2023-41159