CVE-2011-1682
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
13/04/2011
Last modified:
11/04/2025
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in phpList 2.10.13 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create a list or (2) insert cross-site scripting (XSS) sequences. NOTE: this issue exists because of an incomplete fix for CVE-2011-0748. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tincan:phplist:*:*:*:*:*:*:*:* | 2.10.13 (including) | |
| cpe:2.3:a:tincan:phplist:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.2b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.3b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.4b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.5b:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.1.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.3.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.3.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:tincan:phplist:1.5.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/44041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66816
- http://secunia.com/advisories/44041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66816



