In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
https://mail.python.org/archives/list/mailman-announce@python.org/thread/JKRWKP4BTVLYNRXV5WU6BJATLZONX3KQ/ https://bugs.launchpad.net/mailman/+bug/1952384 https://bazaar.launchpad.net/~mailman-coders/mailman/2.1/revision/1882