Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33064
HistoryNov 23, 2021 - 2:50 a.m.

Information Disclosure

2021-11-2302:50:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
mailman bionic csrf token encryption brute-force attacks admin password software

EPSS

0.001

Percentile

43.9%

mailman:bionic is vulnerable to information disclosure. The CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password enabling brute-force attacks.