Access Control Issue in phpList Affects Super Admin Accounts
CVE-2023-27576

6.7MEDIUM

Key Information:

Vendor

PHPlist

Status
Vendor
CVE Published:
18 August 2023

What is CVE-2023-27576?

An access control vulnerability in phpList prior to version 3.6.14 allows attackers to manipulate super admin account settings. By exploiting improper handling of update requests, an attacker can change the super admin's email address and perform a password reset, resulting in unauthorized access to the super admin account. This exploit involves altering the ID and username parameters to bypass email confirmation, effectively leading to an account takeover. It is crucial for users to update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.