Description
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Remediation
References
Related Vulnerabilities
Jenkins Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-43497)
WebLogic CVE-2023-22031 Vulnerability (CVE-2023-22031)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3369)
WordPress Plugin Contact Form 7-Clockwork SMS Cross-Site Scripting (2.3.0)