PT-2020-14165 · Phplist · Phplist

Dino Covotsos

·

Published

2020-07-08

·

Updated

2024-03-06

·

CVE-2020-15073

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpList versions prior to 3.5.5
Description An issue was discovered that allows for an XSS vulnerability to occur within the Import Administrators section via the upload of an edited text document. This issue also affects the Subscriber Lists section.
Recommendations For versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-PHPLIST-2020-15073
CVE-2020-15073

Affected Products

Phplist