/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon