GHSA-q6pp-9mv4-x9xpHighCVSS 8.1

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.

🔗 References (7)