It was discovered that Smarty, that is integrated in the PostfixAdmin
code, was not properly sanitizing user input when generating templates. An
attacker could, through PHP injection, possibly use this issue to execute
arbitrary code. (CVE-2022-29221)
It was discovered that Moment.js, that is integrated in the PostfixAdmin
code, was using an inefficient parsing algorithm when processing date
strings in the RFC 2822 standard. An attacker could possibly use this
issue to cause a denial of service. (CVE-2022-31129)
It was discovered that Smarty, that is integrated in the PostfixAdmin
code, was not properly escaping JavaScript code. An attacker could
possibly use this issue to conduct cross-site scripting attacks (XSS).
(CVE-2023-28447)
More Stories
mupdf-1.24.6-4.fc41
FEDORA-2025-7d002ee0e7 Packages in this update: mupdf-1.24.6-4.fc41 Update description: fix CVE-2024-46657 (rhbz#2331627) Read More
golang-github-aws-sdk-2-20250103-1.fc42 golang-github-rclone-gofakes3-0.0.3-1.fc42 rclone-1.68.2-1.fc42
FEDORA-2025-9b0b1cc333 Packages in this update: golang-github-aws-sdk-2-20250103-1.fc42 golang-github-rclone-gofakes3-0.0.3-1.fc42 rclone-1.68.2-1.fc42 Update description: Fix for CVE-2024-52522 Read More
suricata-7.0.8-1.el8
FEDORA-EPEL-2025-02e26b51d5 Packages in this update: suricata-7.0.8-1.el8 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.fc40
FEDORA-2025-aa783e1cbd Packages in this update: suricata-7.0.8-1.fc40 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.el9
FEDORA-EPEL-2025-9dfb7c8f88 Packages in this update: suricata-7.0.8-1.el9 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More
suricata-7.0.8-1.fc41
FEDORA-2025-e24171db6d Packages in this update: suricata-7.0.8-1.fc41 Update description: Various security, performance, accuracy, and stability issues have been fixed. Read More