CVE-2011-0707 is not related to this CSRF issue. It references an XSS
vulnerability that was fixed in Mailman 2.1.15 and so noted in the
changelog of that release at https://launchpad.net/mailman/2.1/2.1.15

CVE-2016-7123 is a new CVE that apparently just acknowledging the CSRF
vulnerability in the admin interface that exists in Mailman prior to
2.1.15. See https://bugs.launchpad.net/mailman/+bug/775294

-- 
You received this bug notification because you are a member of Mailman
Coders, which is subscribed to GNU Mailman.
https://bugs.launchpad.net/bugs/1614841

Title:
  CSRF protection needs to be extended to the user options page

To manage notifications about this bug go to:
https://bugs.launchpad.net/mailman/+bug/1614841/+subscriptions
_______________________________________________
Mailman-coders mailing list
[email protected]
https://mail.python.org/mailman/listinfo/mailman-coders

Reply via email to