PT-2012-3973 · Renaud Bastide Christophe Wolfhugel · Sympa
Micah Anderson
·
Publicado
2012-05-31
·
Atualizado
2012-08-14
·
CVE-2012-2352
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sympa versions prior to 6.1.11
Description
The issue concerns the archive management page in Sympa, where a lack of permission checks allows remote attackers to perform unauthorized actions on list archives. This can be achieved through vectors related to the
do arc manage, do arc download, or do arc delete functions.Recommendations
For versions prior to 6.1.11, update to version 6.1.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the archive management page to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sympa