6.5
CVSSv3

CVE-2018-13796

Published: 12/07/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in GNU Mailman prior to 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailman

Vendor Advisories

Synopsis Moderate: mailman security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for mailman is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) ba ...
Debian Bug report logs - #903674 mailman: CVE-2018-13796: Arbitrary text injection vulnerability in Mailman CGIs Package: src:mailman; Maintainer for src:mailman is Mailman for Debian <pkg-mailman-hackers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Jul 2018 19:42:01 UT ...
Several security issues were fixed in Mailman ...
A cross-site scripting vulnerability (XSS) has been discovered in mailman due to the host_name field not being properly validated A malicious list owner could use this flaw to create a specially crafted list and inject client-side scripts (CVE-2018-0618) An issue was discovered in GNU Mailman before 2128 A crafted URL can cause arbitrary text ...
Cross-site scripting vulnerability in Mailman 2126 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors (CVE-2018-0618) An issue was discovered in GNU Mailman before 2128 A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site (CVE-2018-13796) ...
An issue was discovered in GNU Mailman before 2128 A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site ...