Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5950

Опубликовано: 23 янв. 2018
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mailmanfixed1:2.1.26-1package

Примечания

  • https://mail.python.org/pipermail/mailman-users/2018-February/083011.html

  • Patch: https://launchpadlibrarian.net/355686141/options.patch

  • https://bugs.launchpad.net/mailman/+bug/1747209

EPSS

Процентиль: 83%
0.02136
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

CVSS3: 6.1
redhat
больше 7 лет назад

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

CVSS3: 6.1
nvd
больше 7 лет назад

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

suse-cvrf
около 7 лет назад

Security update for mailman

CVSS3: 6.1
github
около 3 лет назад

Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.

EPSS

Процентиль: 83%
0.02136
Низкий