[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

252097

 
 

909

 
 

196747

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2020-1536 --- mailman

ID: oval:org.secpod.oval:def:1700453Date: (C)2020-11-05   (M)2023-12-20
Class: PATCHFamily: unix




A cross-site scripting vulnerability has been discovered in mailman due to the host_name field not being properly validated. A malicious list owner could use this flaw to create a specially crafted list and inject client-side scripts. An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site

Platform:
Amazon Linux 2
Product:
mailman
Reference:
ALAS2-2020-1536
CVE-2018-0618
CVE-2018-13796
CVE    2
CVE-2018-0618
CVE-2018-13796

© SecPod Technologies