CVE-2011-1682

phpList <2.10.13 - CSRF

Title source: llm

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC
htmlwebappsphp
https://www.exploit-db.com/exploits/18419

Scores

EPSS 0.0040
EPSS Percentile 60.2%

Classification

CWE
CWE-352
Status draft

Affected Products (50)

tincan/phplist < 2.10.13
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
... and 35 more

Timeline

Published Apr 13, 2011
Tracked Since Feb 18, 2026