PT-2021-10858 · Phplist · Phplist
R0Ck3T1973
·
Published
2021-07-01
·
Updated
2024-03-06
·
CVE-2020-23208
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
phplist version 3.5.3
Description
A stored cross site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the
Send test field under the Start or continue campaign module.Recommendations
For phplist version 3.5.3, consider disabling the
Send test field in the Start or continue campaign module until a patch is available to prevent exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phplist