CVE-2015-1306Sensitive Information Exposure in Sympa

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 30.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22
Latest updateMay 17

Description

The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/sympa< sympa 6.1.23~dfsg-2 (bookworm)
Debiansympa/sympa< 6.1.23~dfsg-2+3
NVDsympa/sympa34 versions+33

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pc42-5rch-8w56: The newsletter posting area in the web interface in Sympa 62022-05-17
OSV
CVE-2015-1306: The newsletter posting area in the web interface in Sympa 62015-01-22

📋Vendor Advisories

1
Debian
CVE-2015-1306: sympa - The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 an...2015
CVE-2015-1306 — Sensitive Information Exposure in Sympa | cvebase