Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-0618

Опубликовано: 22 июн. 2018
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

A cross-site scripting vulnerability (XSS) has been discovered in mailman due to the host_name field not being properly validated. A malicious list owner could use this flaw to create a specially crafted list and inject client-side scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5mailmanWill not fix
Red Hat Enterprise Linux 6mailmanWill not fix
Red Hat Enterprise Linux 8mailmanNot affected
Red Hat Enterprise Linux 7mailmanFixedRHSA-2020:105431.03.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1596458mailman: Cross-site scripting vulnerability allows malicious listowners to inject scripts into listinfo pages

EPSS

Процентиль: 67%
0.00536
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 7 лет назад

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
nvd
больше 7 лет назад

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS3: 5.4
debian
больше 7 лет назад

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allow ...

suse-cvrf
больше 7 лет назад

Security update for mailman

CVSS3: 5.4
github
больше 3 лет назад

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS

Процентиль: 67%
0.00536
Низкий

4.8 Medium

CVSS3