CVE-2012-2741: XSS
Cross-site scripting (XSS) vulnerability in publichtml/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2741?
CVE-2012-2741 is classified as a moderate-severity cross-site scripting (XSS) vulnerability.
How does CVE-2012-2741 affect phpList installations?
CVE-2012-2741 allows remote attackers to inject arbitrary web scripts or HTML into affected phpList installations via the num parameter.
How do I fix CVE-2012-2741?
To fix CVE-2012-2741, update phpList to version 2.10.18 or later.
Which versions of phpList are affected by CVE-2012-2741?
CVE-2012-2741 affects phpList versions prior to 2.10.18, including all minor versions starting from 2.10.1 up to 2.10.17.
What is the impact of exploiting CVE-2012-2741?
Exploiting CVE-2012-2741 can lead to unauthorized script execution in a user’s browser, potentially compromising user sessions or data.