Access Control Issue in phpList Affects Super Admin Accounts
CVE-2023-27576
6.7MEDIUM
What is CVE-2023-27576?
An access control vulnerability in phpList prior to version 3.6.14 allows attackers to manipulate super admin account settings. By exploiting improper handling of update requests, an attacker can change the super admin's email address and perform a password reset, resulting in unauthorized access to the super admin account. This exploit involves altering the ID and username parameters to bypass email confirmation, effectively leading to an account takeover. It is crucial for users to update to the latest version to mitigate this risk.
