PT-2025-37150 · Vinzzb+1 · Phplist Subber+1
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PhpList Subber versions prior to 1.2
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
bulk action handler() function. This allows unauthenticated attackers to trigger bulk synchronization of subscription forms by tricking a site administrator into clicking a forged link. Nonce validation is a security measure used to ensure that a request was intentionally sent by the user and not forged by a third party.Recommendations
Update the plugin to a version later than 1.1.
As a temporary workaround, restrict access to the
bulk action handler() function until the update is applied.Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phplist Subber
Phpls