cbcvebase.
CVE-2018-1000550
published 2018-06-26

CVE-2018-1000550: The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can…

PriorityP351critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.58%
83.4th percentile
The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiansympa< sympa 6.2.32~dfsg-1 (bookworm)sympa 6.2.32~dfsg-1 (bookworm)
sympasympa< 6.2.326.2.32
sympasympa>= 0 < 6.2.32~dfsg-16.2.32~dfsg-1
sympasympa>= 0 < 6.2.32~dfsg-16.2.32~dfsg-1
sympasympa>= 0 < 6.2.32~dfsg-16.2.32~dfsg-1
sympasympa>= 0 < 6.2.32~dfsg-16.2.32~dfsg-1
sympasympa>= 0 < 6.1.17~dfsg-1ubuntu0.1~esm16.1.17~dfsg-1ubuntu0.1~esm1
sympasympa>= 0 < 6.1.24~dfsg-1ubuntu0.1~esm16.1.24~dfsg-1ubuntu0.1~esm1
sympasympa>= 0 < 6.2.24~dfsg-1ubuntu0.1~esm16.2.24~dfsg-1ubuntu0.1~esm1
sympasympa>= 0 < 6.2.40~dfsg-4ubuntu0.20.04.1~esm16.2.40~dfsg-4ubuntu0.20.04.1~esm1

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.