Impact
The vulnerability lies in the way phpList before version 3.6.17 handles the CSRF token in the mass subscriber removal form. Because the token is not validated, an attacker can craft a page that, when a logged‑in administrator visits it, silently submits a request to remove and blacklist subscriber addresses. This leads to unauthorized deletion of data and loss of subscriber information—an integrity‑focused impact rooted in Cross‑Site Request Forgery (CWE‑352).
Affected Systems
The flaw affects all phpList releases older than 3.6.17, including the 3.6.0 through 3.6.16 series and earlier. Administrators using any of these versions are vulnerable to this CSRF-based mass removal attack.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate severity, while an EPSS score of less than 1% suggests a low probability of widespread exploitation as of the current data. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need an authenticated administrator’s session to trigger the malicious request, typically by luring the user to a crafted link or embedded image. Given the moderate severity, the low exploitation likelihood does not eliminate the risk, and patching is strongly advised.
OpenCVE Enrichment