ホーム
» GitHub Security Advisories
» GHSA-rh6c-jh4c-9fg3
説明
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
基本情報
タイプ
reviewed
深刻度
medium
GitHub 上のアドバイザリ
アドバイザリを開く ↗
リポジトリのアドバイザリ
—
ソースコード
ソースを見る ↗
公開(アドバイザリ)
2022-04-29 02:59:06 UTC
更新
2023-09-18 22:51:56 UTC
GitHub レビュー済み
2023-09-18 22:51:56 UTC
NVD で公開
2005-01-10
EPSS Score
Score
Percentile
1.58%
81.51%
CVSS Scores
No CVSS scores in this advisory.
CWEs
CWE id
Name
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected packages (1)
Vulnerable version ranges and first patched releases as published by GitHub.
Ecosystem
Package
Vulnerable range
First patched
Vulnerable functions
pip
mailman
< 2.1.5
2.1.5
—
cvelogic
Threat Intelligence