Description
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
Remediation
References
Related Vulnerabilities
PrestaShop Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-20717)
Ruby Numeric Errors Vulnerability (CVE-2011-0188)
WordPress Plugin WP Mail Logging Cross-Site Scripting (1.8.2)
WordPress Plugin Auto Featured Image Arbitrary File Upload (1.2)
LimeSurvey Incorrect Default Permissions Vulnerability (CVE-2019-16186)