First published: Tue Jul 06 2021(Updated: )
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | =3.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-22249 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2020-22249, upgrade phplist to version 3.5.2 or later where the vulnerability has been addressed.
Exploitation of CVE-2020-22249 can lead to unauthorized remote code execution on the affected server.
CVE-2020-22249 is present in phplist version 3.5.1.
CVE-2020-22249 specifically affects phplist 3.5.1, and other versions may not be impacted unless they share the same vulnerability.