Description
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server Use After Free Vulnerability (CVE-2019-10082)
Oracle JRE CVE-2013-2432 Vulnerability (CVE-2013-2432)
WordPress Plugin Strong Testimonials Multiple Cross-Site Scripting Vulnerabilities (2.31.4)
WordPress Plugin Tweet Blender Cross-Site Scripting (4.0.1)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1429)