CVE-2021-43331

Related Vulnerabilities: CVE-2021-43331  

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

Description

The MITRE CVE dictionary describes this issue as:

In GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS.

Additional Information

  • Bugzilla 2027222: CVE-2021-43331 mailman: XSS in Cgi/options.py via crafted URL
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • FAQ: Frequently asked questions about CVE-2021-43331