CVE-2017-20033: PHPList Reflected cross site scriting
A vulnerability classified as problematic has been found in PHPList 3.2.6. This affects an unknown part of the file /lists/admin/. The manipulation of the argument page with the input send\'\";><script>alert(8)</script> leads to cross site scripting (Reflected). It is possible to initiate the attack remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20033?
CVE-2017-20033 is classified as a problematic vulnerability indicating a moderate level of risk.
How can I fix CVE-2017-20033?
To fix CVE-2017-20033, upgrade PHPList to version 3.2.6 or later, as updates may contain security patches.
What type of vulnerability is CVE-2017-20033?
CVE-2017-20033 is a cross-site scripting (Reflected) vulnerability.
What component of PHPList is affected by CVE-2017-20033?
CVE-2017-20033 affects the admin section of PHPList, specifically the file located at /lists/admin/.
What can be exploited through CVE-2017-20033?
CVE-2017-20033 can be exploited through manipulating the 'page' parameter to inject malicious scripts.