PT-2020-14164 · Phplist · Phplist

Dino Covotsos

·

Published

2020-07-08

·

Updated

2024-03-06

·

CVE-2020-15072

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpList versions prior to 3.5.5
Description An error-based SQL Injection issue exists via the Import Administrators section, allowing potential exploitation.
Recommendations For versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-PHPLIST-2020-15072
BIT-PHPLIST-2020-15073
CVE-2020-15072

Affected Products

Phplist