QID 995358
Date Published: 2023-09-22
QID 995358: Python (Pip) Security Update for mailman (GHSA-rh6c-jh4c-9fg3)
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rh6c-jh4c-9fg3 for updates and patch information.
Vendor References
- GHSA-rh6c-jh4c-9fg3 -
github.com/advisories/GHSA-rh6c-jh4c-9fg3
CVEs related to QID 995358
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rh6c-jh4c-9fg3 | mailman |
|