GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used. |
References |
|
Thu, 24 Apr 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gnu
Gnu mailman |
|
CPEs | cpe:2.3:a:gnu:mailman:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gnu
Gnu mailman |
Mon, 21 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. |
Mon, 21 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 20 Apr 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-20T00:00:00.000Z
Updated: 2025-04-28T13:44:29.998Z
Reserved: 2025-04-19T00:00:00.000Z
Link: CVE-2025-43920

Updated: 2025-04-21T14:37:02.012Z

Status : Modified
Published: 2025-04-20T01:15:45.867
Modified: 2025-04-28T14:15:22.323
Link: CVE-2025-43920

No data.