CVE-2018-13796: Input Validation
Published Jul 12, 2018
·Updated
An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
Affected Software
2 affected components
debian/mailman
GNU Mailman<2.1.28
Event History
Jul 12, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·03:04 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·03:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-13796.
2
What is the severity level of CVE-2018-13796?
The severity level of CVE-2018-13796 is medium.
3
What is the affected software version range for CVE-2018-13796?
The affected software version range for CVE-2018-13796 is from GNU Mailman before 2.1.28.
4
How can a crafted URL exploit CVE-2018-13796?
A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site, exploiting CVE-2018-13796.
5
Where can I find more information about CVE-2018-13796?
More information about CVE-2018-13796 can be found at the following references: [link1] [link2] [link3].