PT-2022-7908 · Phplist · Phplist
Tim Coen
·
Published
2022-06-10
·
Updated
2022-06-17
·
CVE-2017-20035
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHPList version 3.2.6
Description
A problematic issue has been found in the Subscribe component of PHPList, affecting the processing of the file /lists/admin/. This leads to cross site scripting (Persistent) and can be initiated remotely.
Recommendations
For PHPList version 3.2.6, upgrade to version 3.3.1 to address this issue. It is recommended to upgrade the affected component.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phplist