Loading vulnerability details…
361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
802
This Week
2 results · Page 1/1
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
open_newsletter
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
open_newsletter