<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PhpList (&lt; 3.6.17) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/phplist--3.6.17/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 21:58:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/phplist--3.6.17/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CSRF Vulnerability in phpList Mass Subscriber Removal</title><link>https://feed.craftedsignal.io/briefs/2026-09-phplist-csrf/</link><pubDate>Wed, 16 Sep 2026 21:58:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-phplist-csrf/</guid><description>phpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.</description><content:encoded><![CDATA[<p>phpList versions before 3.6.17 contain a vulnerability in the mass subscriber removal form handler, where the application fails to properly validate cross-site request forgery (CSRF) tokens. This security flaw enables a remote, unauthenticated attacker to induce an already logged-in administrator to perform unauthorized actions by visiting a specially crafted malicious webpage. Upon the administrator's interaction with this page, the application processes the removal and blacklisting of arbitrary subscriber addresses silently and without further authentication or validation prompts. This issue poses a significant risk to subscriber list integrity, potentially resulting in mass data loss or administrative disruption within marketing campaigns. Organizations utilizing affected versions of phpList should prioritize upgrading to version 3.6.17 or later to address the missing token validation mechanism.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized deletion and permanent blacklisting of subscriber records. This can lead to the loss of entire mailing list segments, disruption of legitimate marketing activities, and administrative burden to recover subscriber data. The vulnerability is particularly severe for organizations relying on phpList for time-sensitive or critical communication.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of phpList to version 3.6.17 or later immediately to patch CVE-2026-92806.</li>
<li>Audit access logs for suspicious administrative activity occurring during off-hours or from anomalous IP addresses to identify potential prior abuse.</li>
<li>Implement strict Content Security Policy (CSP) headers on administrative dashboards to mitigate the impact of malicious cross-site scripting or redirection attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>csrf</category><category>patch-management</category></item></channel></rss>