Impact
The flaw in phpList versions older than 3.7.0‑RC5 allows a remote attacker to delete bounce rules by abusing a missing CSRF check on the bouncerule deletion endpoint. A crafted GET request with a del parameter and no token can remove arbitrary rows from the phplist_bounceregex table when an authenticated administrator innocently loads the URL. This unauthorized removal of bounce rules can break bounce handling and potentially lead to email delivery issues, an inference rather than a directly stated consequence.
Affected Systems
The vulnerability affects all installations of phpList version 3.x earlier than 3.7.0‑RC5, regardless of the host operating system or web server. Administrators who have enabled the default deletion functionality on bouncerules.php are at risk. No specific platform or environment is excluded, so any deployed instance of the affected phpList releases is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate impact. Exploitation requires that the attacker successfully convince an administrator to load the malicious URL, so it is limited to environments with at least one privileged user. Because the EPSS data is not available, the likelihood of exploitation cannot be quantified, but the lack of CISA KEV listing suggests no large‑scale incidents have been reported. Nevertheless, the potential for disrupting bounce processing warrants attention.
OpenCVE Enrichment