CSRF Vulnerability in GNU Mailman Affects Admin Panel Security
CVE-2021-43332
6.5MEDIUM
What is CVE-2021-43332?
In GNU Mailman versions prior to 2.1.36, a vulnerability exists in the CSRF token for the Cgi/admindb.py admin database page, which inadvertently contains an encrypted version of the list admin password. This vulnerability may allow a moderator to exploit this weakness through an offline brute-force attack, potentially compromising the security of user sessions and access control within the Mailman administration interface.