Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh6c-jh4c-9fg3

Опубликовано: 29 апр. 2022
Источник: github
Github: Прошло ревью

Описание

mailman Cross-site scripting (XSS) vulnerability

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

Пакеты

Наименование

mailman

pip
Затронутые версииВерсия исправления

< 2.1.5

2.1.5

EPSS

Процентиль: 81%
0.01585
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

redhat
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

nvd
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

debian
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the driver script in mailm ...

EPSS

Процентиль: 81%
0.01585
Низкий

Дефекты

CWE-79