Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Sympa < 4.1.3 List Creation Description Field XSS

Medium

Synopsis

The remote host is vulnerable to a Cross-Site Scripting (XSS) attack.

Description

The remote host is running wwsympa.fcgi, a web interface for the Sympa mailing list manager. It is reported that this version of Sympa may permit an attacker to inject malicious HTML in "List Info" page through the description field of the list creation form. This field is not sanitized properly by the CGI.

Solution

Upgrade to version 4.1.3 or higher.