[Mailman-Users] Malicious Third-Party Unsubscription Requests

2022-07-09 Thread Karl Semich
list administrator to enable, to require my password to be provided before the confirmations are sent to me? If this configuration option does not exist yet, could anybody advise what sourcefiles would need modification so as to contribute it as a feature addition? Thanks a bunch, Karl S

[Mailman-Users] DOS vulnerability, gmail and yahoo

2023-09-19 Thread Karl Semich
Hi mailman-users, So you know, it looks like there is a vulnerability with mailman 2 where a third party can very aggressively spoof password reminder, unsubscription, or other requests using the web interface, queueing tens of thousands of unsolicited messages to any given subscriber. Worse, if