PT-2010-4537 · Gnu+2 · Gnu Mailman+2

Mark Sapiro

·

Published

2010-09-15

·

Updated

2023-02-13

·

CVE-2010-3089

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GNU Mailman versions prior to 2.1.14rc1
Description The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote authenticated users to inject arbitrary web script or HTML. This can be achieved through vectors involving the list information field or the list description field.
Recommendations For GNU Mailman versions prior to 2.1.14rc1, update to version 2.1.14rc1 or later to resolve the issue. As a temporary workaround, consider restricting access to the list information and description fields to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1141
CVE-2010-3089
DSA-2170-1
RHSA-2011:0307
RHSA-2011:0308
RHSA-2011_0307
RHSA-2011_0308

Affected Products

Alt Linux
Gnu Mailman
Red Hat