Debian Linux Security Advisory 4108-1 - Calum Hutton and the Mailman team discovered a cross site scripting and information leak vulnerability in the user options page. A remote attacker could use a crafted URL to steal cookie information or to fish for whether a user is subscribed to a list with a private roster.
9d35d5ad565bca8c1f75bbba0777b61cfc5cb238a65a157dc896ba52dd6acfff