{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/phplist--3.7.0-rc5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-73482"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["phpList (\u003c 3.7.0-RC5)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","csrf","php"],"_cs_type":"threat","_cs_vendors":["phpList"],"content_html":"\u003cp\u003ephpList versions prior to 3.7.0-RC5 contain a cross-site request forgery (CSRF) vulnerability located in the administrative management module, specifically within 'lists/admin/admins.php'. The vulnerability stems from an insecure implementation of the administrator deletion action, which is triggered via a GET request using the parameter '?page=admins\u0026amp;delete=N'. While phpList includes a central 'verifyCsrfGetToken' check, this implementation sets 'enforce=false', effectively bypassing protection if the token parameter is omitted from the request. A remote attacker can exploit this by deceiving a logged-in super-administrator into accessing a crafted URL - such as one embedded as an image source or hidden iframe within a phishing email - to silently remove existing administrator accounts from the system. This threat is particularly critical for self-hosted instances where administrative control is concentrated in a single super-administrator account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized deletion of administrative accounts within the phpList instance. This can lead to administrative lockout, service disruption, and the potential for an attacker to gain further unauthorized access if accounts are recreated with compromised credentials or if administrative roles are altered during the incident. There is no evidence of widespread exploitation in the wild, but the impact is significant for organizations relying on phpList for email campaign management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade phpList installations to version 3.7.0-RC5 or later to resolve the underlying CSRF vulnerability.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs in phpList for anomalous deletion activities initiated via GET requests.\u003c/li\u003e\n\u003cli\u003eImplement additional authentication controls for administrative actions that modify user roles or delete accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T19:44:01Z","date_published":"2026-08-13T19:44:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-phplist-csrf/","summary":"A CSRF vulnerability in phpList versions prior to 3.7.0-RC5 allows authenticated administrators to be tricked into deleting other administrator accounts via a crafted GET request.","title":"Cross-Site Request Forgery in phpList Administrator Deletion","url":"https://feed.craftedsignal.io/briefs/2026-08-phplist-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - PhpList (\u003c 3.7.0-RC5)","version":"https://jsonfeed.org/version/1.1"}