CVE-2025-43919
MEDIUMGNU Mailman < 2.1.39 - Path Traversal
Title source: ruleDescription
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
Exploits (3)
github
WORKING POC
1 stars
by JawadPy · pythonpoc
https://github.com/JawadPy/CVE-Exploit-Collection/tree/main/CVE-2025-43919.txt
nomisec
WORKING POC
by cybersecplayground · poc
https://github.com/cybersecplayground/CVE-2025-43919-POC
References (4)
Scores
CVSS v3
5.8
EPSS
0.0022
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Details
CWE
CWE-22
CWE-24
Status
published
Products (1)
gnu/mailman
2.1.1 - 2.1.39
Published
Apr 20, 2025
Tracked Since
Feb 18, 2026