Description
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
Joomla! Core Arbitrary File Upload (2.5.0 - 3.8.7)
PostgreSQL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2020-25694)
MySQL Other Vulnerability (CVE-1999-1188)
WordPress Plugin TheCartPress eCommerce Shopping Cart Order Information Security Bypass (1.1.9.2)
TYPO3 Improper Input Validation Vulnerability (CVE-2010-4068)