[Mailman-Users] Roster security

Rubén Fernández Asensio enseikou at gmail.com
Mon May 21 03:27:29 EDT 2018


OK, that was what I meant. Not the actual options page but the options 
login page, with the buttons to unsubscribe and send the password.

Yeah, I'm aware that only the concerned subscriber will receive the 
password reminder and the unsubscribe confirmation, so there's no 
security hole, but anyway it puzzles me that subscribers can "spam" each 
other this way.

But if it's supposed to be this way, I guess I'll have to live with it.

El 20/05/18 a les 20:56, Robert Heller ha escrit:
> And yes the "options login page" also contains an "unsubscribe" button.  But
> as Mark says, you need the user's list password for anything to actually
> happen.


More information about the Mailman-Users mailing list