CVE-2018-0618

Cross-site scripting vulnerability in Mailman 2.1.26 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
gnumailman
𝑥
≤ 2.1.26
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mailman
artful
ignored
bionic
Fixed 1:2.1.26-1ubuntu0.1
released
cosmic
ignored
disco
not-affected
eoan
not-affected
focal
not-affected
trusty
dne
xenial
Fixed 1:2.1.20-1ubuntu0.4
released
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
mailman
RHEL 7
3:2.1.15-30.el7
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
mailman
Amazon Linux 1
4:2.1.15-30.25.amzn1
fixed
Amazon Linux 2
3:2.1.15-30.amzn2
fixed
mailman-debuginfo
Amazon Linux 1
4:2.1.15-30.25.amzn1
fixed
Amazon Linux 2
3:2.1.15-30.amzn2
fixed