CVE-2018-5950
Description
Cross-site scripting vulnerability in Mailman's web UI via crafted user-options URL allows arbitrary script execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting vulnerability in Mailman's web UI via crafted user-options URL allows arbitrary script execution.
Vulnerability
Mailman versions prior to 2.1.26 contain a reflected cross-site scripting (XSS) vulnerability in the web UI. An attacker can inject arbitrary web script or HTML via a crafted user-options URL [1], [4]. The issue is present in the way the web interface processes parameters without proper sanitization.
Exploitation
The attacker does not require authentication; the vulnerability can be exploited by tricking a user into clicking a specially crafted link to a Mailman user-options page [3]. No special network position is needed beyond the ability to deliver the link (e.g., via email or other channels). The crafted URL includes encoded script that executes in the victim's browser.
Impact
Successful exploitation allows the attacker to execute arbitrary HTML or JavaScript in the context of the victim's browser session. This could lead to session hijacking, defacement, or further attacks against the Mailman instance [4]. Additionally, an information leak was reported where a user-options URL with a VARHELP query fragment bypasses authentication, exposing list membership details [4].
Mitigation
The fix was released in Mailman version 2.1.26 [4]. Red Hat has issued updates for RHEL 7 (mailman-2.1.15-26.el7_4.1) [1]. Ubuntu has provided updated packages (mailman 1:2.1.20-1ubuntu1.2 for 16.04 LTS) [3]. Users should upgrade to the patched version or apply the relevant vendor patch.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18- osv-coords17 versionspkg:rpm/suse/mailman&distro=SUSE%20Enterprise%20Storage%204pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATApkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSSpkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/mailman&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/mailman&distro=SUSE%20OpenStack%20Cloud%207
< 2.1.17-3.3.3+ 16 more
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.15-9.6.6.1
- (no CPE)range: < 2.1.15-9.6.6.1
- (no CPE)range: < 2.1.15-9.6.6.1
- (no CPE)range: < 2.1.15-9.6.6.1
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.15-9.6.6.1
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
- (no CPE)range: < 2.1.17-3.3.3
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
9- access.redhat.com/errata/RHSA-2018:0504mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2018:0505mitrevendor-advisoryx_refsource_REDHAT
- usn.ubuntu.com/3563-1/mitrevendor-advisoryx_refsource_UBUNTU
- www.debian.org/security/2018/dsa-4108mitrevendor-advisoryx_refsource_DEBIAN
- packetstormsecurity.com/files/159761/Mailman-2.1.23-Cross-Site-Scripting.htmlmitrex_refsource_MISC
- www.securityfocus.com/bid/104594mitrevdb-entryx_refsource_BID
- bugs.launchpad.net/mailman/+bug/1747209mitrex_refsource_CONFIRM
- lists.debian.org/debian-lts-announce/2018/02/msg00007.htmlmitremailing-listx_refsource_MLIST
- www.mail-archive.com/mailman-users%40python.org/msg70375.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.