Showing 3 vulnerabilities on this page for Mailman

Signals CISA KEV Ransomware Nuclei
GNU vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CWE-863Apr 20, 2025
CVSS5.3v3.1EPSS0.432%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CWE-78Apr 20, 2025
CVSS5.4v3.1EPSS0.562%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CWE-22CWE-24Apr 20, 2025
CVSS5.8v3.1EPSS1.35%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX