ISOMAN

CVE

CVE-2020-15011

GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.

Severity
MEDIUM
CVSS
4.3
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
  2. http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
  3. https://bugs.launchpad.net/mailman/+bug/1877379
  4. https://lists.debian.org/debian-lts-announce/2020/06/msg00036.html
  5. https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
  6. https://usn.ubuntu.com/4406-1/
  7. https://www.debian.org/security/2021/dsa-4991
  8. http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00047.html
  9. http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00063.html
  10. https://bugs.launchpad.net/mailman/+bug/1877379
  11. https://lists.debian.org/debian-lts-announce/2020/06/msg00036.html
  12. https://lists.debian.org/debian-lts-announce/2020/07/msg00007.html
  13. https://usn.ubuntu.com/4406-1/
  14. https://www.debian.org/security/2021/dsa-4991