HIGH
squirrelmail: persistent XSS in message display the formaction attribute
Published Aug 5, 2018
8.7
HIGHCVSS 3.0
EPSS 1.65%
Description
The mail message display page in SquirrelMail through 1.4.22 has XSS via the formaction attribute.
Affected products
No data.
- ≤ 1.4.22
No data.
Red Hat Enterprise Linux 5
squirrelmail
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | squirrelmail | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of squirrelmail as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Extended Life Phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Weaknesses (1)
References (10)
- http://www.openwall.com/lists/oss-security/2018/07/26/2 x_refsource_MISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-14954 Vendor Advisory
- https://bugs.debian.org/905023 x_refsource_MISCIssue TrackingMailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1616096 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6836 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVXTYMZ35IC5KPNMAE6BWAQWURMX7KZO/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5FP5O562A4FM5TCFNEW73SS6PZONSAC/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-14954
- https://sourceforge.net/p/squirrelmail/bugs/2831/ x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14954
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2018/07/26/2 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-14954 | Vendor Advisory | |
| https://bugs.debian.org/905023 | x_refsource_MISCIssue TrackingMailing ListThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1616096 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-6836 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVXTYMZ35IC5KPNMAE6BWAQWURMX7KZO/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5FP5O562A4FM5TCFNEW73SS6PZONSAC/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14954 | ||
| https://sourceforge.net/p/squirrelmail/bugs/2831/ | x_refsource_MISCExploitIssue TrackingPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-14954 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 5, 2018
Updated Aug 5, 2024
Reserved Aug 5, 2018
Link CVE-2018-14954
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-6836 Assigner mitre
Published Aug 5, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-6836