CVE-2025-43920
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
20/04/2025
Last modified:
20/04/2025
Description
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM