CVE-2020-12639: XSS
Published May 4, 2020
·Updated
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
Affected Software
1 affected component
PHPlist PHPList<3.5.3
Event History
May 4, 2020
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12639?
The severity of CVE-2020-12639 is rated as medium with a CVSS score of 6.1.
2
How can I fix the vulnerability CVE-2020-12639 in phpList?
To fix CVE-2020-12639, update phpList to version 3.5.3 or higher.