First published: Sun Apr 20 2025(Updated: )
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
cPanel GNU Mailman | ||
cPanel GNU Mailman | >=2.1.1<=2.1.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43921 is a high-severity vulnerability that allows unauthenticated attackers to create email lists.
To mitigate CVE-2025-43921, you should upgrade to the latest version of GNU Mailman that addresses this vulnerability.
CVE-2025-43921 specifically affects GNU Mailman version 2.1.39 and earlier versions deployed in certain configurations.
This vulnerability can lead to unauthorized list creation, which could result in spam distribution or further exploitation.
Yes, CVE-2025-43921 is a public vulnerability, and proof-of-concept exploits are available, making it critical to apply patches immediately.