CVE-2017-20030: PHPList Sending Campain sql injection
A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the component Sending Campain. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20030?
CVE-2017-20030 is classified as critical due to its potential for remote SQL injection.
How do I fix CVE-2017-20030?
To fix CVE-2017-20030, update your PHPList installation to a version higher than 3.2.6 that addresses this vulnerability.
What component is affected by CVE-2017-20030?
CVE-2017-20030 affects the Sending Campaign component located in the /lists/admin/ directory of PHPList.
Can CVE-2017-20030 be exploited remotely?
Yes, CVE-2017-20030 can be exploited remotely, making it a significant security risk.
What type of vulnerability is CVE-2017-20030?
CVE-2017-20030 is a SQL injection vulnerability that allows attackers to manipulate database queries.