CVE-2025-43921

MEDIUM

GNU Mailman < 2.1.39 - Incorrect Authorization

Title source: rule

Description

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

Exploits (1)

nomisec WRITEUP
by 0NYX-MY7H · poc
https://github.com/0NYX-MY7H/CVE-2025-43921

Scores

CVSS v3 5.3
EPSS 0.0042
EPSS Percentile 61.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
gnu/mailman 2.1.1 - 2.1.39
Published Apr 20, 2025
Tracked Since Feb 18, 2026