Sympa version 6.2.16 and later contains a URL Redirection to Untrusted Site vulnerability in the referer parameter of the wwsympa fcgi login action that can result in open redirection and reflected cross-site scripting via data URIs.
View the template here CVE-2018-1000671.yaml
References:
https://lists.debian.org/debian-lts-announce/2018/09/msg00023.html