CVE-2018-0618: XSS
Published Jul 26, 2018
·Updated
Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
4 affected components
debian/mailman
GNU Mailman<=2.1.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Jul 26, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:43 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·03:04 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-0618?
CVE-2018-0618 is a cross-site scripting vulnerability in Mailman 2.1.26 and earlier.
2
Who can exploit CVE-2018-0618?
Remote authenticated attackers can exploit CVE-2018-0618.
3
How can attackers exploit CVE-2018-0618?
Attackers can inject arbitrary web script or HTML through unspecified vectors.
4
What is the severity of CVE-2018-0618?
The severity of CVE-2018-0618 is medium, with a CVSS severity value of 5.4.
5
Where can I find more information about CVE-2018-0618?
You can find more information about CVE-2018-0618 at the following references: [1] http://jvn.jp/en/jp/JVN00846677/index.html [2] https://lists.debian.org/debian-lts-announce/2018/07/msg00034.html [3] https://mail.python.org/pipermail/mailman-announce/2018-June/000236.html