Sympa version 6.2.16 and later contains a URL Redirection to Untrusted Site vulnerability in the referer parameter of the wwsympa fcgi login action that can result in open redirection and reflected cross-site scripting via data URIs.
id: CVE-2018-1000671
info:
name: Sympa version =>6.2.16 - Cross-Site Scripting
author: 0x_Akoko
...