CVE-2016-7123
published 2016-09-02CVE-2016-7123: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of…
PriorityP340high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.53%
71.8th percentile
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | mailman | <= 2.1.14 | — |
| gnu | mailman | >= 0 < 1:2.1.16-2ubuntu0.1 | 1:2.1.16-2ubuntu0.1 |
| gnu | mailman | >= 0 < 1:2.1.16-2ubuntu0.2 | 1:2.1.16-2ubuntu0.2 |
| gnu | mailman | >= 0 < 1:2.1.20-1ubuntu0.1 | 1:2.1.20-1ubuntu0.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mailman vulnerabilities
vendor_ubuntu·2016-11-01·CVSS 8.8
CVE-2016-6893 [HIGH] Mailman vulnerabilities
Title: Mailman vulnerabilities
Summary: Several security issues were fixed in Mailman.
It was discovered that the Mailman administrative web interface did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could perform administrative
actions. This issue only affected Ubuntu 12.04 LTS. (CVE-2016-7123)
Nishant Agarwala discovered that the Mailman user options page did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could modify user options.
(CVE-2016-6893)
Instructions: In general, a standard system update will make all the neces
Red Hat
mailman: Missing CSRF protection in admin web interface
vendor_redhat·2016-08-23·CVSS 8.8
CVE-2016-7123 [HIGH] CWE-352 mailman: Missing CSRF protection in admin web interface
mailman: Missing CSRF protection in admin web interface
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
Package: mailman (Red Hat Enterprise Linux 5) - Will not fix
Package: mailman (Red Hat Enterprise Linux 6) - Will not fix
Package: mailman (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-8p5c-w6j3-96pw: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2
ghsa_unreviewed·2022-05-17
CVE-2016-7123 [HIGH] CWE-352 GHSA-8p5c-w6j3-96pw: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
OSV
mailman vulnerabilities
osv·2016-11-01·CVSS 8.8
CVE-2016-7123 [HIGH] mailman vulnerabilities
mailman vulnerabilities
It was discovered that the Mailman administrative web interface did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could perform administrative
actions. This issue only affected Ubuntu 12.04 LTS. (CVE-2016-7123)
Nishant Agarwala discovered that the Mailman user options page did not
protect against cross-site request forgery (CSRF) attacks. If an
authenticated user were tricked into visiting a malicious website while
logged into Mailman, a remote attacker could modify user options.
(CVE-2016-6893)
OSV
CVE-2016-7123: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2
osv·2016-09-02·CVSS 8.8
CVE-2016-7123 [HIGH] CVE-2016-7123: Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
No detection rules found.
No public exploits indexed.
2016-09-02
Published