Description
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Human Resource Management Security Bypass (2.2.14)
WordPress Plugin WPUpper Share Buttons Cross-Site Scripting (3.42)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6625)