ZeroHour

CVE-2020-29668

PoC
CVSS 3.1
3.7 low
EPSS
2%p79
Published
()
Modified
Description

Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

Vendors
sympafedoraprojectdebian
Products
sympa, fedora, debian linux
Weakness
CWE-287, CWE-565
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.