GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to reproduce this, regardless of whether cPanel or WHM is used.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://code.launchpad.net/~mailman-coders/mailman/2.1 | product |
https://github.com/0NYX-MY7H/CVE-2025-43921 | third party advisory exploit |
https://github.com/cpanel/mailman2-python3 | |
https://www.openwall.com/lists/oss-security/2025/04/21/6 |