CVE-2018-1000550Path Traversal in Sympa

CWE-22Path Traversal8 documents5 sources
Severity
9.8CRITICALNVD
EPSS
0.4%
top 36.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26
Latest updateMay 13

Description

The Sympa Community Sympa version prior to version 6.2.32 contains a Directory Traversal vulnerability in wwsympa.fcgi template editing function that can result in Possibility to create or modify files on the server filesystem. This attack appear to be exploitable via HTTP GET/POST request. This vulnerability appears to have been fixed in 6.2.32.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDsympa/sympa< 6.2.32
debiandebian/sympa< sympa 6.2.32~dfsg-1 (bookworm)
Debiansympa/sympa< 6.2.32~dfsg-1+3
Ubuntusympa/sympa< 6.1.17~dfsg-1ubuntu0.1~esm1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4fwc-r99f-85f4: The Sympa Community Sympa version prior to version 62022-05-13
OSV
sympa vulnerabilities2021-03-15
OSV
sympa vulnerabilities2020-07-28
OSV
CVE-2018-1000550: The Sympa Community Sympa version prior to version 62018-06-26

📋Vendor Advisories

3
Ubuntu
Sympa vulnerabilities2021-03-15
Ubuntu
Sympa vulnerabilities2020-07-28
Debian
CVE-2018-1000550: sympa - The Sympa Community Sympa version prior to version 6.2.32 contains a Directory T...2018
CVE-2018-1000550 — Path Traversal in Sympa | cvebase