CVE-2018-5950: XSS
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
Other sources
Cross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Reference:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888201
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/mailmanto a version that resolves this vulnerability.Fixed in 2.1.26 - Upgrade
Upgrade
debian/mailmanto a version that resolves this vulnerability.Fixed in 1:2.1.26-1Fixed in 1:2.1.23-1+deb9u2Fixed in 1:2.1.18-2+deb8u2 - Upgrade
Upgrade
Mailmanto a version that resolves this vulnerability.Fixed in 2.1.26
Event History
Frequently Asked Questions
What is CVE-2018-5950?
CVE-2018-5950 is a cross-site scripting (XSS) vulnerability in the web UI in Mailman before version 2.1.26, which allows remote attackers to inject arbitrary web script or HTML via a user-options URL.
How severe is CVE-2018-5950?
CVE-2018-5950 has a severity score of 6.1, which is considered medium.
Which software versions are affected by CVE-2018-5950?
Mailman versions before 2.1.26 are affected by CVE-2018-5950.
How can I fix CVE-2018-5950?
To fix CVE-2018-5950, you should update Mailman to version 2.1.26 or apply the recommended security patches provided by your operating system vendor.
Where can I find more information about CVE-2018-5950?
You can find more information about CVE-2018-5950 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/159761/Mailman-2.1.23-Cross-Site-Scripting.html), [SecurityFocus](http://www.securityfocus.com/bid/104594), [RedHat Security Advisory](https://access.redhat.com/errata/RHSA-2018:0504).