CVE-2018-1000671
Sympa version =>6.2.16 - Cross-Site Scripting
Record summary
CVE-2018-1000671 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSympa version =>6.2.16 - Cross-Site ScriptingCVSS 6.1
Sympa version 6.2.16 and later contains a URL Redirection to Untrusted Site vulnerability in the referer parameter of the wwsympa fcgi login action that can result in open redirection and reflected cross-site scripting via data URIs.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to a patched version of Sympa (>=6.2.17) or apply the necessary security patches provided by the vendor.
Source: ProjectDiscovery