PT-2022-7909 · Phplist · Phplist
Tim Coen
·
Published
2022-06-10
·
Updated
2022-06-17
·
CVE-2017-20036
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHPList versions 3.2.6
Description
A vulnerability was found in the Bounce Rule component of the /lists/admin/ file, which can lead to cross site scripting (Persistent). The manipulation can be launched remotely.
Recommendations
For PHPList version 3.2.6, upgrade to version 3.3.1 to address this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phplist