Vulnerabilities (CVE)

Filtered by vendor Sympa Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-46900 1 Sympa 1 Sympa 2024-01-10 N/A 7.5 HIGH
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.
CVE-2020-9369 3 Debian, Fedoraproject, Sympa 3 Debian Linux, Fedora, Sympa 2022-01-01 5.0 MEDIUM 7.5 HIGH
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
CVE-2020-26880 1 Sympa 1 Sympa 2021-05-09 7.2 HIGH 7.8 HIGH
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
CVE-2020-10936 1 Sympa 1 Sympa 2020-12-24 7.2 HIGH 7.8 HIGH
Sympa before 6.2.56 allows privilege escalation.