4.3
CVSSv2

CVE-2020-12108

Published: 06/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

/options/mailman in GNU Mailman prior to 2.1.31 allows Arbitrary Content Injection.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu mailman

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

opensuse leap 15.1

opensuse backports sle 15.0

opensuse leap 15.2

canonical ubuntu linux 18.04

canonical ubuntu linux 16.04

Vendor Advisories

Mailman could be made to inject arbitrary content in the login page if it received a specially crafted input ...
Several vulnerabilities were discovered in mailman, a web-based mailing list manager, which could result in arbitrary content injection via the options and private archive login pages, and CSRF attacks or privilege escalation via the user options page For the oldstable distribution (buster), these problems have been fixed in version 1:2129-1+deb ...