CVE-2011-1682: XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1682?
CVE-2011-1682 has a medium severity rating, indicating potential exploitation risks that could lead to unauthorized access or actions by an attacker.
How do I fix CVE-2011-1682?
To fix CVE-2011-1682, upgrade to the latest version of phpList that is not vulnerable, specifically version 2.10.14 or higher.
What types of attacks can exploit CVE-2011-1682?
CVE-2011-1682 can be exploited through cross-site request forgery (CSRF) attacks, potentially leading to unauthorized actions by an administrator.
Which versions of phpList are affected by CVE-2011-1682?
CVE-2011-1682 affects phpList versions 2.10.13 and earlier, including older versions such as 1.5.0 to 2.10.13.
Is my phpList installation safe from CVE-2011-1682 if I have other security measures in place?
While other security measures may help, the only effective solution against CVE-2011-1682 is to upgrade to a patched version of phpList.