Description
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Remediation
References
Related Vulnerabilities
WordPress Plugin Site Reviews CSV Injection (6.2.0)
Grafana Improper Synchronization Vulnerability (CVE-2023-2801)
MediaWiki Resource Management Errors Vulnerability (CVE-2015-6733)
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.4)
WordPress Plugin Simple Link Directory Cross-Site Scripting (7.3.4)