Description
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2007-3856)
Apache HTTP Server Use of Uninitialized Resource Vulnerability (CVE-2020-1934)
WebLogic Deserialization of Untrusted Data Vulnerability (CVE-2018-3245)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2531)