Description
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4400)
WordPress Plugin OMGF-Host Google Fonts Locally Multiple Vulnerabilities (4.5.3)
Omeka Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5100)
WordPress Plugin Frontend File Manager Multiple Vulnerabilities (21.2)