A crafted URL to the Cgi/options.py user options page can execute arbitrary JavaScript for XSS. External Reference: https://bugs.launchpad.net/mailman/+bug/1949401
Created mailman tracking bugs for this issue: Affects: fedora-33 [bug 2027223] Affects: fedora-34 [bug 2027224]