Description
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Remediation
References
Related Vulnerabilities
Drupal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-25277)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2018-20826)
MySQL CVE-2022-21323 Vulnerability (CVE-2022-21323)
XWiki Credentials Management Errors Vulnerability (CVE-2005-4862)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5339)