PT-2021-19562 · Phplist · Phplist

Published

2021-01-21

·

Updated

2024-03-06

·

CVE-2021-3188

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: phpList version 3.6.0
Description: The issue allows for CSV injection, related to the email parameter, and affects the /lists/admin/ endpoint.
Recommendations: For phpList version 3.6.0, consider restricting access to the /lists/admin/ endpoint and avoid using the email parameter until a fix is available. As a temporary workaround, restrict the export functionality in the /lists/admin/ endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BIT-PHPLIST-2021-3188
CVE-2021-3188

Affected Products

Phplist