GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.
Metrics
Affected Vendors & Products
References
History
Sun, 20 Apr 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. | |
Weaknesses | CWE-24 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-20T00:25:05.231Z
Reserved: 2025-04-19T00:00:00.000Z
Link: CVE-2025-43919

No data.

Status : Received
Published: 2025-04-20T01:15:45.233
Modified: 2025-04-20T01:15:45.233
Link: CVE-2025-43919

No data.