Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to the credentials of a victim's account.
2016-09-02T14:59:09.283
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gnu | mailman | 2.1 | Yes |
| Application | gnu | mailman | 2.1.1 | Yes |
| Application | gnu | mailman | 2.1.2 | Yes |
| Application | gnu | mailman | 2.1.3 | Yes |
| Application | gnu | mailman | 2.1.4 | Yes |
| Application | gnu | mailman | 2.1.5 | Yes |
| Application | gnu | mailman | 2.1.6 | Yes |
| Application | gnu | mailman | 2.1.8 | Yes |
| Application | gnu | mailman | 2.1.9 | Yes |
| Application | gnu | mailman | 2.1.10 | Yes |
| Application | gnu | mailman | 2.1.10 | Yes |
| Application | gnu | mailman | 2.1.10b1 | Yes |
| Application | gnu | mailman | 2.1.10b3 | Yes |
| Application | gnu | mailman | 2.1.10b4 | Yes |
| Application | gnu | mailman | 2.1.11 | Yes |
| Application | gnu | mailman | 2.1.11 | Yes |
| Application | gnu | mailman | 2.1.11 | Yes |
| Application | gnu | mailman | 2.1.12 | Yes |
| Application | gnu | mailman | 2.1.12 | Yes |
| Application | gnu | mailman | 2.1.12 | Yes |
| Application | gnu | mailman | 2.1.13 | Yes |
| Application | gnu | mailman | 2.1.13 | Yes |
| Application | gnu | mailman | 2.1.14 | Yes |
| Application | gnu | mailman | 2.1.14 | Yes |
| Application | gnu | mailman | 2.1.14-1 | Yes |
| Application | gnu | mailman | 2.1.15 | Yes |
| Application | gnu | mailman | 2.1.15 | Yes |
| Application | gnu | mailman | 2.1.16 | Yes |
| Application | gnu | mailman | 2.1.16 | Yes |
| Application | gnu | mailman | 2.1.16 | Yes |
| Application | gnu | mailman | 2.1.16 | Yes |
| Application | gnu | mailman | 2.1.17 | Yes |
| Application | gnu | mailman | 2.1.18 | Yes |
| Application | gnu | mailman | 2.1.18 | Yes |
| Application | gnu | mailman | 2.1.18 | Yes |
| Application | gnu | mailman | 2.1.18 | Yes |
| Application | gnu | mailman | 2.1.18-1 | Yes |
| Application | gnu | mailman | 2.1.19 | Yes |
| Application | gnu | mailman | 2.1.19 | Yes |
| Application | gnu | mailman | 2.1.19 | Yes |
| Application | gnu | mailman | 2.1.19 | Yes |
| Application | gnu | mailman | 2.1.20 | Yes |
| Application | gnu | mailman | 2.1.21 | Yes |
| Application | gnu | mailman | 2.1.21 | Yes |
| Application | gnu | mailman | 2.1.22 | Yes |
| Application | gnu | mailman | 2.1.23 | Yes |