0NYX-MY7H/CVE-2025-43921

0NYX-MY7H/CVE-2025-43921

Releases0
CVE-2025-43921: Unauthorized Mailing List Creation in GNU Mailman 2.1.39

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.