The CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack. External Reference: https://bugs.launchpad.net/mailman/+bug/1949403
Created mailman tracking bugs for this issue: Affects: fedora-33 [bug 2027226] Affects: fedora-34 [bug 2027227]