An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon