CVE-2021-46900: XSS
Published Dec 31, 2023
·Updated
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.
Affected Software
1 affected component
sympa sympa<6.2.62
Event History
Dec 31, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-46900?
CVE-2021-46900 is classified as a moderate severity vulnerability impacting password security and XSS protection.
2
How do I fix CVE-2021-46900?
To fix CVE-2021-46900, upgrade Sympa to version 6.2.62 or later.
3
What systems are affected by CVE-2021-46900?
CVE-2021-46900 affects all versions of Sympa prior to 6.2.62.
4
What risks does CVE-2021-46900 pose?
CVE-2021-46900 poses risks related to password integrity and potential Cross-Site Scripting (XSS) vulnerabilities.
5
Is there a workaround for CVE-2021-46900?
There is no official workaround for CVE-2021-46900; upgrading to the latest version is recommended.