PT-2020-13708 · Phplist · Phplist

Carlos Ramã­Rez L

·

Published

2020-06-04

·

Updated

2024-03-06

·

CVE-2020-13827

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpList versions prior to 3.5.4
Description The issue allows for XSS attacks via the "/lists/admin/user.php" and "/lists/admin/users.php" API endpoints. This can potentially lead to malicious script execution.
Recommendations For versions prior to 3.5.4, update to version 3.5.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/lists/admin/user.php" and "/lists/admin/users.php" endpoints until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PHPLIST-2020-13827
CVE-2020-13827

Affected Products

Phplist