Lucene search

K
cvelistVulDBCVELIST:CVE-2017-20030
HistoryJun 10, 2022 - 9:30 a.m.

CVE-2017-20030 PHPList Sending Campain sql injection

2022-06-1009:30:30
CWE-89
VulDB
www.cve.org
3
phplist
sending campaign
sql injection
remote attack
upgrade

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

AI Score

8

Confidence

High

EPSS

0.001

Percentile

37.8%

A vulnerability was found in PHPList 3.2.6. It has been classified as critical. Affected is an unknown function of the file /lists/admin/ of the component Sending Campain. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.

CNA Affected

[
  {
    "product": "PHPList",
    "vendor": "unspecified",
    "versions": [
      {
        "status": "affected",
        "version": "3.2.6"
      }
    ]
  }
]

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

AI Score

8

Confidence

High

EPSS

0.001

Percentile

37.8%

Related for CVELIST:CVE-2017-20030