4.3
CVSSv2

CVE-2018-5950

Published: 23/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the web UI in Mailman prior to 2.1.26 allows remote malicious users to inject arbitrary web script or HTML via a user-options URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailman

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 14.04

canonical ubuntu linux 17.10

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server aus 7.4

redhat enterprise linux server eus 7.4

redhat enterprise linux server tus 7.4

redhat enterprise linux server eus 7.5

redhat enterprise linux server tus 7.6

redhat enterprise linux server eus 7.6

redhat enterprise linux server aus 7.6

Vendor Advisories

Debian Bug report logs - #888201 mailman: CVE-2018-5950 Package: src:mailman; Maintainer for src:mailman is Mailman for Debian <pkg-mailman-hackers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 23 Jan 2018 21:27:02 UTC Severity: grave Tags: security, upstream Found in ver ...
Mailman could be made to run arbitrary code ...
Synopsis Moderate: mailman security update Type/Severity Security Advisory: Moderate Topic An update for mailman is now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Moderate: mailman security update Type/Severity Security Advisory: Moderate Topic An update for mailman is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of moderate A Common Vulnerability Scoring System (CVSS) base score, wh ...
Calum Hutton and the Mailman team discovered a cross site scripting and information leak vulnerability in the user options page A remote attacker could use a crafted URL to steal cookie information or to fish for whether a user is subscribed to a list with a private roster For the oldstable distribution (jessie), this problem has been fixed in ve ...
Cross-site scripting (XSS) vulnerability in web UIA cross-site scripting (XSS) flaw was found in mailman An attacker, able to trick the user into visiting a specific URL, can execute arbitrary web scripts on the user's side and force the victim to perform unintended actions (CVE-2018-5950) ...
Cross-site scripting (XSS) vulnerability in web UIA cross-site scripting (XSS) flaw was found in mailman An attacker, able to trick the user into visiting a specific URL, can execute arbitrary web scripts on the user's side and force the victim to perform unintended actions (CVE-2018-5950) CSRF protection missing in the user options pageCross-sit ...
A cross-site scripting (XSS) flaw was found in mailman An attacker, able to trick the user into visiting a specific URL, can execute arbitrary web scripts on the user's side and force the victim to perform unintended actions ...

Exploits

Mailman versions 1x up through 2123 suffer from a cross site scripting vulnerability ...