5.8
CVSSv2

CVE-2018-1000671

Published: 06/09/2018 Updated: 09/11/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sympa sympa

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #908165 sympa: CVE-2018-1000671 Package: src:sympa; Maintainer for src:sympa is Debian Sympa team <sympa@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Sep 2018 20:39:02 UTC Severity: important Tags: fixed-upstream, security, upstream Found in versi ...