7.5
CVSSv2

CVE-2018-1000550

Published: 26/06/2018 Updated: 04/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.

Vulnerable Product Search on Vulmon Subscribe to Product

sympa sympa

debian debian linux 8.0

Vendor Advisories

Michael Kaczmarczik discovered a vulnerability in the web interface template editing function of Sympa, a mailing list manager Owner and listmasters could use this flaw to create or modify arbitrary files in the server with privileges of sympa user or owner view list config files even if edit_listconf prohibits it For the stable distribution (st ...