Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 536189) +++ security/vuxml/vuln.xml (working copy) @@ -168871,6 +168871,35 @@ 2005-09-29 + + + sympa -- Denial of service caused by malformed CSRF token + + + sympa + 6.2.54 + + + + +

Javier Moreno discovered a vulnerability in Sympa web interface that can cause + denial of service (DoS) attack.

+

By submitting requests with malformed parameters, this flaw allows to create + junk files in Sympa’s directory for temporary files. And particularly by + tampering token to prevent CSRF, it allows to originate exessive notification + messages to listmasters.

+ +
+ + CVE-2020-9369 + https://sympa-community.github.io/security/2020-001.html + + + 2020-02-24 + 2020-05-22 + +
+