PT-2020-5770 · Sympa · Sympa
Racke
·
Published
2020-11-24
·
Updated
2022-04-26
·
CVE-2020-29668
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Sympa versions prior to 6.2.59b.2
Description:
The issue is related to the
authenticateAndRun function in the Sympa mailing list manager, which lacks proper cookie value validation. This allows a remote attacker to gain access to confidential data by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. This can provide full SOAP API access.Recommendations:
For versions prior to 6.2.59b.2, update to version 6.2.59b.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the
authenticateAndRun function until a patch is available.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sympa