Description
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
Remediation
References
Related Vulnerabilities
Ruby on Rails Uncontrolled Resource Consumption Vulnerability (CVE-2026-33169)
WordPress Plugin OptionTree Cross-Site Scripting (2.5.5)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9854)
PostgreSQL Integer Overflow or Wraparound Vulnerability (CVE-2026-6473)
WordPress Plugin Event Registration 'event_id' Parameter SQL Injection (5.32)