CVE-2020-15073: XSS
Published Jul 8, 2020
·Updated
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
Affected Software
1 affected component
PHPlist PHPList<=3.5.4
Event History
Jul 8, 2020
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15073?
The severity of CVE-2020-15073 is classified as medium due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2020-15073?
To fix CVE-2020-15073, upgrade phpList to version 3.5.5 or newer.
3
What components of phpList are affected by CVE-2020-15073?
CVE-2020-15073 affects the Import Administrators section and the Subscriber Lists section of phpList.
4
What type of vulnerability is CVE-2020-15073?
CVE-2020-15073 is an XSS (cross-site scripting) vulnerability.
5
Can CVE-2020-15073 be exploited remotely?
Yes, CVE-2020-15073 can be exploited remotely through the upload functionality in the affected sections.