Description
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.
Remediation
References
Related Vulnerabilities
Apache Traffic Server Other Vulnerability (CVE-2019-9513)
MyBB Improper Privilege Management Vulnerability (CVE-2018-1000503)
MediaWiki Uncontrolled Resource Consumption Vulnerability (CVE-2021-46149)
Microsoft SQL Server Other Vulnerability (CVE-2003-0231)
WordPress Plugin All in One Social Lite Server-Side Request Forgery (1.0)