Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32858
HistoryNov 09, 2021 - 1:50 p.m.

Cross-Site Scripting (XSS)

2021-11-0913:50:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
cross-site scripting
gnu mailman
vulnerability
mime type
web browser
javascript

EPSS

0.012

Percentile

85.2%

GNU Mailman is vulnerable to cross-site scripting. The vulnerability exists due to HTTP reply from an archive web server lacking a MIME type, and a web browser performing MIME sniffing may conclude that the MIME type should have been text/html, and execute JavaScript code.