A vulnerability classified as problematic was found in phpList up to 3.7.0-RC4. This affects an unknown function of the file lists/admin/admins.php of the component Administrator Deletion. The manipulation results in cross-site request forgery.
This vulnerability is known as CVE-2026-73482. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.