CVE-2014-2916: CSRF
Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a request to admin/.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2916?
CVE-2014-2916 is classified as a medium severity vulnerability due to its potential impact on administrator authentication.
How do I fix CVE-2014-2916?
To fix CVE-2014-2916, upgrade phpList to version 3.0.6 or later to mitigate the CSRF vulnerability.
What types of attacks can exploit CVE-2014-2916?
CVE-2014-2916 can be exploited through cross-site request forgery attacks targeting the subscription page editor.
Who is affected by CVE-2014-2916?
Administrators of phpList versions prior to 3.0.6 are at risk of having their authentication hijacked due to CVE-2014-2916.
What is the impact of CVE-2014-2916 on phpList?
The impact of CVE-2014-2916 includes the potential unauthorized actions taken on behalf of an authenticated administrator.