CVE-2012-5228: XSS
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the testtarget parameter. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5228?
CVE-2012-5228 is considered a high severity vulnerability due to its potential for remote code execution via cross-site scripting (XSS).
How do I fix CVE-2012-5228?
To fix CVE-2012-5228, upgrade to PHPList version 2.10.19 or later, which resolves the XSS vulnerability.
What is affected by CVE-2012-5228?
CVE-2012-5228 affects PHPList versions 2.10.9, 2.10.17, and earlier, potentially including other versions before 2.10.19.
What type of vulnerability is CVE-2012-5228?
CVE-2012-5228 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web script or HTML.
How can attackers exploit CVE-2012-5228?
Attackers can exploit CVE-2012-5228 by injecting malicious code via the testtarget parameter in the URL, which could compromise user data.