First published: Wed Jul 08 2020(Updated: )
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | <=3.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15072 is categorized as a medium severity vulnerability due to its potential for SQL injection.
To fix CVE-2020-15072, you should upgrade phpList to version 3.5.5 or later.
CVE-2020-15072 affects phpList versions up to and including 3.5.4.
Yes, if exploited, CVE-2020-15072 may allow an attacker to execute arbitrary SQL commands, potentially leading to data loss.
The attack vector for CVE-2020-15072 is through the Import Administrators section of phpList.