CVE-2021-40347 is a medium-severity vulnerability affecting GNU Mailman Postorius before version 1.3.5. An authenticated attacker can send a crafted POST request to unsubscribe any user from a mailing list, and this action also reveals if the user was subscribed. The vulnerability has a CVSS score of 5.4, indicating low impact on confidentiality and integrity, and it does not appear to be actively exploited. There is no publicly available exploit code, nor has it garnered significant community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.5CPE matchmatch criteria | cpe:2.3:a:postorius_project:postorius:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.