mailman Cross-site scripting (XSS) vulnerability

説明

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

基本情報

タイプ
reviewed
深刻度
medium
GitHub 上のアドバイザリ
アドバイザリを開く ↗
リポジトリのアドバイザリ
ソースコード
ソースを見る ↗
公開(アドバイザリ)
2022-04-29 02:59:06 UTC
更新
2023-09-18 22:51:56 UTC
GitHub レビュー済み
2023-09-18 22:51:56 UTC
NVD で公開
2005-01-10

EPSS Score

Score Percentile
1.58% 81.51%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
pip mailman < 2.1.5 2.1.5

References

cvelogic Threat Intelligence