First published: Fri Jun 10 2022(Updated: )
A vulnerability, which was classified as problematic, was found in PHPList 3.2.6. Affected is an unknown function of the file /lists/admin/ of the component Bounce Rule. The manipulation leads to cross site scripting (Persistent). It is possible to launch the attack remotely. Upgrading to version 3.3.1 is able to address this issue. It is recommended to upgrade the affected component.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | =3.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-20036 is classified as a problematic vulnerability due to its potential for persistent cross-site scripting attacks.
To fix CVE-2017-20036, users should upgrade PHPList to the latest version that addresses this vulnerability.
CVE-2017-20036 specifically affects PHPList version 3.2.6.
CVE-2017-20036 is associated with persistent cross-site scripting (XSS) attacks.
Yes, CVE-2017-20036 can be exploited remotely, making it a significant security concern.