Safety vulnerability ID: 62668
The information on this page was manually curated by our Cybersecurity Intelligence Team.
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Latest version: 3.3.10
Mailman -- the GNU mailing list manager
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application