Description
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
WordPress Multiple Cross-Site Scripting Vulnerabilities (2.0.11 - 2.3)
WordPress Plugin Simple:Press-WordPress Forum Arbitrary File Upload (6.6.0)
Ruby Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-10933)
WordPress Plugin PowerPack Pro for Elementor Privilege Escalation (2.10.14)
PHP Improper Input Validation Vulnerability (CVE-2021-21705)