CVE-2011-1682
phpList <2.10.13 - CSRF
Title source: llmDescription
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
Scores
EPSS
0.0040
EPSS Percentile
60.2%
Classification
CWE
CWE-352
Status
draft
Affected Products (50)
tincan/phplist
< 2.10.13
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
tincan/phplist
... and 35 more
Timeline
Published
Apr 13, 2011
Tracked Since
Feb 18, 2026