Vendor
high
advisory
CSRF Vulnerability in phpList Mass Subscriber Removal
1 TTP 1 CVEphpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.
phpList
web-vulnerability
csrf
patch-management
1t
1c
high
threat
Cross-Site Request Forgery in phpList Administrator Deletion
1 CVEA CSRF vulnerability in phpList versions prior to 3.7.0-RC5 allows authenticated administrators to be tricked into deleting other administrator accounts via a crafted GET request.
exploited
phpList
web-vulnerability
csrf
php
1c