PT-2020-6385 · Phplist · Phplist

Geek-Repo

·

Published

2020-05-18

·

Updated

2024-03-06

·

CVE-2020-22251

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions phplist version 3.5.3
Description The issue is related to a lack of protection for the web page structure, allowing a remote attacker to perform cross-site scripting attacks. This can be achieved by creating a new username in the login name field within the Manage Administrators section. The estimated number of potentially affected devices is not provided.
Recommendations For phplist version 3.5.3, consider disabling the ability to add new administrators or restrict access to the Manage Administrators section until a patch is available. Avoid using the login name field in the affected section to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-04423
BIT-PHPLIST-2020-22251
CVE-2020-22251

Affected Products

Phplist