cve/2020/CVE-2020-8547.md
2024-06-09 00:33:16 +00:00

714 B

CVE-2020-8547

Description

phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

POC

Reference

Github