Description
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2009-3291)
WordPress Plugin File Manager Multiple Cross-Site Request Forgery Vulnerabilities (5.0)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000192)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7861)