Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32706
HistoryOct 25, 2021 - 3:38 a.m.

Privilege Escalation

2021-10-2503:38:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
privilege escalation
gnu mailman
csrf
remote attack
account takeover

EPSS

0.003

Percentile

66.2%

GNU Mailman allows remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).