CVE-2017-20034: PHPList List Name Persistent cross site scriting
Published Jun 10, 2022
·Updated
A vulnerability classified as problematic was found in PHPList 3.2.6. This vulnerability affects unknown code of the file /lists/admin/ of the component List Name. The manipulation leads to cross site scripting (Persistent). The attack can be initiated remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
1 affected component
PHPlist PHPList=3.2.6
Event History
Jun 10, 2022
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-20034?
CVE-2017-20034 has been classified as a problematic vulnerability.
2
How do I fix CVE-2017-20034?
To fix CVE-2017-20034, upgrade PHPList to a version newer than 3.2.6.
3
What type of vulnerability is CVE-2017-20034?
CVE-2017-20034 is classified as a cross-site scripting (XSS) vulnerability.
4
Can CVE-2017-20034 be exploited remotely?
Yes, CVE-2017-20034 can be exploited remotely.
5
Which component of PHPList is affected by CVE-2017-20034?
CVE-2017-20034 affects the List Name component in PHPList.