First published: Sun Dec 31 2023(Updated: )
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sympa Sympa | <6.2.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46900 is classified as a moderate severity vulnerability impacting password security and XSS protection.
To fix CVE-2021-46900, upgrade Sympa to version 6.2.62 or later.
CVE-2021-46900 affects all versions of Sympa prior to 6.2.62.
CVE-2021-46900 poses risks related to password integrity and potential Cross-Site Scripting (XSS) vulnerabilities.
There is no official workaround for CVE-2021-46900; upgrading to the latest version is recommended.