An issue exists in views/list.py in GNU Mailman Postorius prior to 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
postorius project postorius |