phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HPhplist
APPPhplist3.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-22249CRITICAL9.8PL ✓same product
RCE w phplist 3.5.1 poprzez upload złośliwego pluginu
CVE-2020-23361CRITICAL9.8PL ✓same product
phpList — pominięcie uwierzytelnienia przez type juggling w porównaniu hashy
CVE-2021-3188CRITICAL9.8PL ✓same product
CSV Injection w phpList 3.6.0 poprzez parametr email i eksport danych
CVE-2017-20029HIGH7.3same product
A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown process...
CVE-2020-35708HIGH7.2same product
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Impo...