Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2016-8001
https://bugs.launchpad.net/bugs/1614841