CVE-2020-35708: SQL Injection
Published Dec 25, 2020
·Updated
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
Affected Software
1 affected component
PHPlist PHPList=3.5.9
Event History
Dec 25, 2020
CVE Published
via MITRE·05:24 AM
Data Sourced
via MITRE·05:24 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35708?
CVE-2020-35708 is classified as a high severity vulnerability due to its potential for SQL injection exploitation.
2
How do I fix CVE-2020-35708?
To fix CVE-2020-35708, upgrade phpList to version 3.5.10 or later, as it contains the necessary patches.
3
Who is affected by CVE-2020-35708?
Administrators using phpList version 3.5.9 are susceptible to CVE-2020-35708 if they import administrators with a crafted file.
4
What type of vulnerability is CVE-2020-35708?
CVE-2020-35708 is an SQL injection vulnerability that allows attackers to manipulate SQL queries.
5
Can CVE-2020-35708 be exploited remotely?
Yes, CVE-2020-35708 can be exploited remotely by an authenticated administrator providing a malicious input.