CVE-2021-40347

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2021
Last modified:
24/09/2021

Description

An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) can send a crafted POST request to unsubscribe any user from a mailing list, also revealing whether that address was subscribed in the first place.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:* 1.3.5 (excluding)