diff options
-rw-r--r-- | Mailman/Cgi/admin.py | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/Mailman/Cgi/admin.py b/Mailman/Cgi/admin.py index d881241c..f3284e17 100644 --- a/Mailman/Cgi/admin.py +++ b/Mailman/Cgi/admin.py @@ -87,7 +87,8 @@ def main(): cgidata = cgi.FieldStorage(keep_blank_values=1) # CSRF check - safe_params = ['VARHELP', 'adminpw', 'admlogin'] + safe_params = ['VARHELP', 'adminpw', 'admlogin', + 'letter', 'chunk', 'findmember'] params = cgidata.keys() if set(params) - set(safe_params): csrf_checked = csrf_check(mlist, cgidata.getvalue('csrf_token')) |