CVE-2011-1682: XSS

Published Apr 13, 2011
·
Updated

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected Software

75 affected components
Tincan Phplist=2.4.0
Tincan Phplist=2.5.6
Tincan Phplist=2.10.6
Tincan Phplist=2.10.3
Tincan Phplist=1.6.1
Tincan Phplist=2.8.2
Tincan Phplist=1.9.0
Tincan Phplist=2.5.5
Tincan Phplist=1.6.0
Tincan Phplist=2.10.10
Tincan Phplist=1.9.3
Tincan Phplist=1.6.3
Tincan Phplist=2.6.3
Tincan Phplist=2.1.0
Tincan Phplist=2.9.4
Tincan Phplist=2.3.1
Tincan Phplist=2.6.5
Tincan Phplist=2.9.3
Tincan Phplist=1.6.4
Tincan Phplist=2.10.9
Tincan Phplist=2.6
Tincan Phplist=2.1.4
Tincan Phplist=2.5.7
Tincan Phplist=2.6.0
Tincan Phplist=1.5.1
Tincan Phplist=1.9.2
Tincan Phplist=2.8.12
Tincan Phplist=2.6.2
Tincan Phplist=2.5.4
Tincan Phplist=1.1.5b
Tincan Phplist=2.10.5
Tincan Phplist=1.4.1
Tincan Phplist=2.1.1
Tincan Phplist=2.4.7
Tincan Phplist=1.1.6
Tincan Phplist=1.8.0
Tincan Phplist=1.7.0
Tincan Phplist=1.7.1
Tincan Phplist=2.1.3
Tincan Phplist=1.1.4b
Tincan Phplist=1.1.5
Tincan Phplist=2.10.2
Tincan Phplist=2.5.2
Tincan Phplist=2.9.5
Tincan Phplist=2.5.0
Tincan Phplist=1.3.5
Tincan Phplist<=2.10.13
Tincan Phplist=2.3.2
Tincan Phplist=2.5.8
Tincan Phplist=2.10.11
Tincan Phplist=2.2.0
Tincan Phplist=2.10.8
Tincan Phplist=2.3.0
Tincan Phplist=1.0
Tincan Phplist=1.5.0
Tincan Phplist=1.1.2b
Tincan Phplist=1.9.1
Tincan Phplist=2.5.1
Tincan Phplist=2.6.4
Tincan Phplist=2.3.4
Tincan Phplist=2.10.12
Tincan Phplist=1.0.1
Tincan Phplist=1.1.7
Tincan Phplist=2.10.4
Tincan Phplist=2.8.7
Tincan Phplist=2.10.1
Tincan Phplist=1.1.3b
Tincan Phplist=2.3.3
Tincan Phplist=2.6.1
Tincan Phplist=1.3.7
Tincan Phplist=2.2.1
Tincan Phplist=2.5.3
Tincan Phplist=2.7.1
Tincan Phplist=2.10.7
Tincan Phplist=2.7.2

Event History

Apr 13, 2011
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-1682?

CVE-2011-1682 has a medium severity rating, indicating potential exploitation risks that could lead to unauthorized access or actions by an attacker.

2

How do I fix CVE-2011-1682?

To fix CVE-2011-1682, upgrade to the latest version of phpList that is not vulnerable, specifically version 2.10.14 or higher.

3

What types of attacks can exploit CVE-2011-1682?

CVE-2011-1682 can be exploited through cross-site request forgery (CSRF) attacks, potentially leading to unauthorized actions by an administrator.

4

Which versions of phpList are affected by CVE-2011-1682?

CVE-2011-1682 affects phpList versions 2.10.13 and earlier, including older versions such as 1.5.0 to 2.10.13.

5

Is my phpList installation safe from CVE-2011-1682 if I have other security measures in place?

While other security measures may help, the only effective solution against CVE-2011-1682 is to upgrade to a patched version of phpList.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203