phpList 3.6.17 之前版本在批量移除订阅者表单处理程序中未能正确验证跨站点请求伪造(CSRF)令牌。攻击者可以诱导已登录的管理员访问特制的页面,从而在未经身份验证的情况下,静默地删除并将任意订阅者邮箱地址加入黑名单。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet