HomeGnuCVE-2025-43919

CVE-2025-43919

MEDIUM
5.8CVSS
Published: 2025-04-20
Updated: 2025-04-28
AI Analysis

Description

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
changed
Confidentiality
low
Integrity
none
Availability
none
Weaknesses
CWE-24CWE-22

Metadata

Primary Vendor
GNU
Published
4/20/2025
Last Modified
4/28/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

gnu : mailman

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-43919 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com