CVE-2025-43920 MEDIUM

CVE-2025-43920

Vendor Gnu
Product Mailman
Weakness CWE-78
Published April 20, 2025
Last update April 28, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

Key dates

02Disclosure timeline

April 20, 2025 CVE published
April 28, 2025 Record updated