Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32705
HistoryOct 25, 2021 - 3:38 a.m.

Privilege Escalation

2021-10-2503:38:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
gnu mailman
privilege escalation
remote
csrf_token
admin password
brute-force attack

EPSS

0.004

Percentile

71.9%

GNU Mailman is vulnerable to allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.