Description
phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.
Remediation
References
Related Vulnerabilities
WordPress Plugin Generate Child Theme Security Bypass (1.5.3)
Ruby on Rails Improper Authentication Vulnerability (CVE-2012-3424)
SharePoint CVE-2020-0975 Vulnerability (CVE-2020-0975)
Chamilo Improper Handling of Case Sensitivity Vulnerability (CVE-2023-3545)
Oracle Database Server CVE-2006-3702 Vulnerability (CVE-2006-3702)