Description
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Appointment Calendar Multiple Cross-Site Scripting Vulnerabilities (2.7.4)
WordPress Plugin Galleries by Angie Makes Cross-Site Scripting (1.67)
WordPress Plugin Monarch Social Sharing Security Bypass (1.2.6)
WordPress Plugin Coming Soon Page & Maintenance Mode Cross-Site Scripting (1.8.1)