CVE-2021-42097
—CVSS 3.1
8.0 high
EPSS
1%p69
Published
()
Modified
Description
GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for account takeover).
In the news0 stories
No ingested article mentions this CVE yet.