Vulnerabilities (CVE)

Filtered by vendor Sympa Subscribe
Filtered by product Sympa
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-26932 2 Debian, Sympa 2 Debian Linux, Sympa 2020-12-24 4.0 MEDIUM 4.3 MEDIUM
debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)
CVE-2018-1000671 2 Debian, Sympa 2 Debian Linux, Sympa 2020-11-09 5.8 MEDIUM 6.1 MEDIUM
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.