Vulnerabilities > CVE-2020-8547 - Type Confusion vulnerability in PHPlist 3.5.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phplist
CWE-843

Summary

phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

Vulnerable Configurations

Part Description Count
Application
Phplist
1