In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
1:2.1.20-11:2.1.20-1ubuntu0.11:2.1.20-1ubuntu0.31:2.1.20-1ubuntu0.41:2.1.20-1ubuntu0.51:2.1.20-1ubuntu0.61:2.1.20-1ubuntu0.6+esm11:2.1.20-1ubuntu0.6+esm21:2.1.23-11:2.1.24-11:2.1.25-11:2.1.26-11:2.1.26-1ubuntu0.11:2.1.26-1ubuntu0.21:2.1.26-1ubuntu0.31:2.1.26-1ubuntu0.41:2.1.26-1ubuntu0.51:2.1.26-1ubuntu0.61:2.1.29-11:2.1.29-1build11:2.1.29-1ubuntu31:2.1.29-1ubuntu3.11:2.1.29-1ubuntu3.1+esm1Exploitability
AV:NAC:LPR:NUI:RScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H