First published: Thu Sep 06 2012(Updated: )
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers to inject arbitrary web script or HTML via the num parameter in a reconcileusers action.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | <=2.10.17 | |
phpList | =2.10.1 | |
phpList | =2.10.2 | |
phpList | =2.10.3 | |
phpList | =2.10.4 | |
phpList | =2.10.5 | |
phpList | =2.10.7 | |
phpList | =2.10.8 | |
phpList | =2.10.9 | |
phpList | =2.10.10 | |
phpList | =2.10.11 | |
phpList | =2.10.12 | |
phpList | =2.10.13 | |
phpList | =2.10.14 | |
phpList | =2.10.15 | |
phpList | =2.10.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2741 is classified as a moderate-severity cross-site scripting (XSS) vulnerability.
CVE-2012-2741 allows remote attackers to inject arbitrary web scripts or HTML into affected phpList installations via the num parameter.
To fix CVE-2012-2741, update phpList to version 2.10.18 or later.
CVE-2012-2741 affects phpList versions prior to 2.10.18, including all minor versions starting from 2.10.1 up to 2.10.17.
Exploiting CVE-2012-2741 can lead to unauthorized script execution in a user’s browser, potentially compromising user sessions or data.