CPE
phpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.