Lucene search

K
osvGoogleOSV:USN-5180-1
HistoryDec 07, 2021 - 5:55 p.m.

mailman vulnerability

2021-12-0717:55:04
Google
osv.dev
9
mailman
csrf
vulnerability
remote attack
admin request

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

44.4%

It was discovered that Mailman incorrectly handled CSRF tokens. A remote
list member or moderator could possibly use their own token to craft an
admin request CSRF attack and set a new admin password or make other
changes.