Sympa before 6.2.62 relies on a cookie parameter for...
High severity
Unreviewed
Published
Dec 31, 2023
to the GitHub Advisory Database
•
Updated Jan 19, 2024
Description
Published by the National Vulnerability Database
Dec 31, 2023
Published to the GitHub Advisory Database
Dec 31, 2023
Last updated
Jan 19, 2024
Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this parameter exists and has an unpredictable value. Specifically, the cookie parameter is both a salt for stored passwords and an XSS protection mechanism.
References