Cross-Site Request Forgery Vulnerability in phpList
CVE-2026-73482
Key Information:
Badges
What is CVE-2026-73482?
A CSRF vulnerability exists in phpList versions prior to 3.7.0-RC5, specifically affecting the lists/admin/admins.php file. This vulnerability allows an attacker to exploit the admin deletion functionality without needing authentication. Through maliciously crafted links, an attacker can trick a logged-in super-administrator into executing a deletion request for any non-self administrator account, resulting in unauthorized removal of administrator profiles.
Affected Version(s)
phplist3 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
