CVE-2023-27576

An issue was discovered in phpList 3.6.12. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phplist:phplist:3.6.12:*:*:*:*:*:*:*

History

21 Nov 2024, 07:53

Type Values Removed Values Added
References () https://cupc4k3.lol/cve-2023-27576-hacking-phplist-how-i-gained-super-admin-access-44c7c90d82da - Exploit, Technical Description, Third Party Advisory () https://cupc4k3.lol/cve-2023-27576-hacking-phplist-how-i-gained-super-admin-access-44c7c90d82da - Exploit, Technical Description, Third Party Advisory
References () https://github.com/phpList/phplist3/pull/986 - () https://github.com/phpList/phplist3/pull/986 -
References () https://www.phplist.org/newslist/phplist-3-6-14-release-notes/ - () https://www.phplist.org/newslist/phplist-3-6-14-release-notes/ -

07 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-639

18 Aug 2023, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-18 15:15

Updated : 2024-11-21 07:53


NVD link : CVE-2023-27576

Mitre link : CVE-2023-27576

CVE.ORG link : CVE-2023-27576


JSON object : View

Products Affected

phplist

  • phplist
CWE
NVD-CWE-noinfo CWE-639

Authorization Bypass Through User-Controlled Key