RULE(RULE ID:338900)

Rule General Information
Release Date: 2025-05-14
Rule Name: GNU Mailman Directory Travesal Vulnerability (CVE-2025-43919)
Severity:
CVE ID:
Rule Protection Details
Description: GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://code.launchpad.net/~mailman-coders/mailman/2.1
https://github.com/0NYX-MY7H/CVE-2025-43919
Solutions
Please refer to announcements or patches release by the vendor: https://list.org/download.html