First published: Mon May 05 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a request to admin/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | <=3.0.5 | |
phpList | =3.0.0 | |
phpList | =3.0.1 | |
phpList | =3.0.2 | |
phpList | =3.0.3 | |
phpList | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2916 is classified as a medium severity vulnerability due to its potential impact on administrator authentication.
To fix CVE-2014-2916, upgrade phpList to version 3.0.6 or later to mitigate the CSRF vulnerability.
CVE-2014-2916 can be exploited through cross-site request forgery attacks targeting the subscription page editor.
Administrators of phpList versions prior to 3.0.6 are at risk of having their authentication hijacked due to CVE-2014-2916.
The impact of CVE-2014-2916 includes the potential unauthorized actions taken on behalf of an authenticated administrator.