CVE-2021-3188: Critical severity PHPlist PHPList vulnerability
Published Jan 21, 2021
·Updated
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Affected Software
1 affected component
PHPlist PHPList=3.6.0
Event History
Jan 21, 2021
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
Description
Jan 26, 2021
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 13, 58461
Event
12:56 PM
Frequently Asked Questions
1
What is the vulnerability ID for phpList 3.6.0?
The vulnerability ID for phpList 3.6.0 is CVE-2021-3188.
2
What is the severity of CVE-2021-3188?
CVE-2021-3188 has a severity level of critical.
3
What is the affected software version for CVE-2021-3188?
The affected software version for CVE-2021-3188 is phpList 3.6.0.
4
What is CSV injection?
CSV injection is a type of attack that occurs when an attacker is able to insert malicious data into a CSV file, which can lead to the execution of arbitrary code.
5
How can I fix the vulnerability in phpList 3.6.0?
To fix the vulnerability in phpList 3.6.0, you should update to a version that is not affected by the vulnerability and follow any recommended security measures provided by the software vendor.