The PHPlist Integration module provides an integration between a Drupal website and phpList newsletter manager. The module provides two main features: user sync and sending a node as a newsletter.
The module introduces a SQL Injection vulnerability to the phpList database. The Drupal database is not affected.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission “administer PHPlist”.
CVE identifier(s) issued
A CVE identifier will be requested, and added upon issuance, in accordance
with Drupal Security Team processes.
Versions affected
PHPlist Integration Module 6.x-1.x versions prior to 6.x-1.7.
Drupal core is not affected. If you do not use the contributed PHPlist Integration Module module, there is nothing you need to do.
Security researchers are tracking a new version of the Emomet malware that is targeting users’ banking credentials and also has the ability to steal email usernames and passwords, which are then used to send spam from compromised accounts. The new variant of Emomet has mostly been seen targeting users in Germany, but researchers at Microsoft […]
AOL has taken steps to stop a set of malicious advertisements being served through their sites, including The Huffington Post, Computer Business Review reports.