GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.
History

Sun, 20 Apr 2025 00:45:00 +0000

Type Values Removed Values Added
Description GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-20T00:27:06.822Z

Reserved: 2025-04-19T00:00:00.000Z

Link: CVE-2025-43920

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-04-20T01:15:45.867

Modified: 2025-04-20T01:15:45.867

Link: CVE-2025-43920

cve-icon Redhat

No data.