.. / CVE-2018-1000671

Exploit for Sympa version =>6.2.16 - Cross-Site Scripting (CVE-2018-1000671)

Description:

Sympa version 6.2.16 and later contains a URL Redirection to Untrusted Site vulnerability in the referer parameter of the wwsympa fcgi login action that can result in open redirection and reflected cross-site scripting via data URIs.

Nuclei Template

View the template here CVE-2018-1000671.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2018/CVE-2018-1000671.yaml
Copy

References:

https://lists.debian.org/debian-lts-announce/2018/09/msg00023.html
https://vuldb.com/?id.123670
https://github.com/sympa-community/sympa/issues/268
https://lists.debian.org/debian-lts-announce/2020/11/msg00015.html
https://nvd.nist.gov/vuln/detail/CVE-2018-1000671