CVE-2020-22251: XSS
Published Jul 6, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in phpList 3.5.3 via the login name field in Manage Administrators when adding a new admin.
Affected Software
1 affected component
PHPlist PHPList<=3.5.3
Event History
Jul 6, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22251?
CVE-2020-22251 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-22251?
To fix CVE-2020-22251, upgrade phpList to version 3.5.4 or later where the vulnerability is patched.
3
What impact does CVE-2020-22251 have on phpList installations?
CVE-2020-22251 allows attackers to inject malicious scripts via the login name field, potentially compromising admin accounts.
4
Which versions of phpList are affected by CVE-2020-22251?
CVE-2020-22251 affects phpList versions up to and including 3.5.3.
5
Where can I find more information about CVE-2020-22251?
More information about CVE-2020-22251 can be found in security advisories and vulnerability databases.