CSRF Vulnerability in GNU Mailman Affects Admin Panel Security
CVE-2021-43332
6.5MEDIUM
Summary
In GNU Mailman versions prior to 2.1.36, a vulnerability exists in the CSRF token for the Cgi/admindb.py admin database page, which inadvertently contains an encrypted version of the list admin password. This vulnerability may allow a moderator to exploit this weakness through an offline brute-force attack, potentially compromising the security of user sessions and access control within the Mailman administration interface.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved