CVE-2025-43920 - CERT CVE
ID CVE-2025-43920
Sažetak GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.
Reference
CVSS
Base: 5.4
Impact: 2.7
Exploitability:2.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Zadnje važnije ažuriranje 21-04-2025 - 16:15
Objavljeno 20-04-2025 - 01:15