Safety vulnerability ID: 25879
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Mailman 2.1.14 includes a fix for CVE-2011-0707: Three XSS flaws due improper escaping of the full name of the member.
Latest version: 3.3.10
Mailman -- the GNU mailing list manager
Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application