CVE-2012-2352: Sympa

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers to list, read, and delete arbitrary list archives via vectors related to the (1) do_arc_manage, (2) do_arc_download, or (3) do_arc_delete functions.

Affected products

  • Sympa Sympa: up to and including 6.1.10; version 0.001 only; version 0.002 only; version 0.003 only; version 0.004 only; version 0.005 only; …

Published 2012-05-31. Last modified 2026-06-16.