CVE-2020-29668

3.7LOW

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

Опубликовано: 12/10/2020Обновлено: 11/21/2024

Описание

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

ИИ-АнализНа базе ИИ

Затронутые продукты

sympasympa
sympasympa
6.2.59
fedoraprojectfedora
32
fedoraprojectfedora
33
debiandebian_linux
9.0
debiandebian_linux
10.0

Ссылки