CVE-2023-27576
Last modified
CVE-2023-27576 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
An issue was discovered in phpList before 3.6.14. Due to an access error, it was possible to manipulate and edit data of the system's super admin, allowing one to perform an account takeover of the user with super-admin permission. Specifically, for a request with updatepassword=1, a modified request (manipulating both the ID parameter and the associated username) can bypass the intended email confirmation requirement. For example, the attacker can start from an updatepassword=1 request with their own ID number, and change the ID number to 1 (representing the super admin account) and change the username to admin2. In the first step, the attacker changes the super admin's email address to one under the attacker's control. In the second step, the attacker performs a password reset for the super admin account. The new password allows login as the super admin, i.e., a successful account takeover.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phplist | Phplist | 3.6.12 |
References
- https://cupc4k3.lol/cve-2023-27576-hacking-phplist-how-i-gained-super-admin-access-44c7c90d82daExploit, Technical Description, Third Party Advisory
- https://cupc4k3.lol/cve-2023-27576-hacking-phplist-how-i-gained-super-admin-access-44c7c90d82daExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-27576?
How severe is CVE-2023-27576?
How do I fix CVE-2023-27576?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-2757The Waiting: One-click countdowns plugin for WordPress is vu…5.4
- CVE-2023-27570The eo_tags package before 1.4.19 for PrestaShop allows SQL …9.8
- CVE-2023-27571An issue was discovered in DG3450 Cable Gateway AR01.02.056.…5.3
- CVE-2023-27572An issue was discovered in CommScope Arris DG3450 Cable Gate…6.1
- CVE-2023-27573netbox-docker before 2.5.0 has a superuser account with defa…9.8
- CVE-2023-27574ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-tas…9.8
- CVE-2023-27577flarum is a forum software package for building communities.…4.9
- CVE-2023-27578Galaxy is an open-source platform for data analysis. All sup…7.5
- CVE-2023-27579TensorFlow is an end-to-end open source platform for machine…7.5
- CVE-2023-2758A denial of service vulnerability exists in Contec CONPROSYS…5.3
- CVE-2023-27580CodeIgniter Shield provides authentication and authorization…5.9
- CVE-2023-27581github-slug-action is a GitHub Action to expose slug value o…8.8
Are you affected by CVE-2023-27576?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
