CVE-2020-15072: SQL Injection
Published Jul 8, 2020
·Updated
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
Affected Software
1 affected component
PHPlist PHPList<=3.5.4
Event History
Jul 8, 2020
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15072?
CVE-2020-15072 is categorized as a medium severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2020-15072?
To fix CVE-2020-15072, you should upgrade phpList to version 3.5.5 or later.
3
What systems are affected by CVE-2020-15072?
CVE-2020-15072 affects phpList versions up to and including 3.5.4.
4
Can CVE-2020-15072 lead to data loss?
Yes, if exploited, CVE-2020-15072 may allow an attacker to execute arbitrary SQL commands, potentially leading to data loss.
5
What is the attack vector for CVE-2020-15072?
The attack vector for CVE-2020-15072 is through the Import Administrators section of phpList.