CVE-2020-23194: XSS
Published Jul 2, 2021
·Updated
A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
1 affected component
PHPlist PHPList<=3.5.4
Remediation
Patch Available
Event History
Jul 2, 2021
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23194?
CVE-2020-23194 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2020-23194?
To mitigate CVE-2020-23194, upgrade to phpList version 3.5.5 or later.
3
Who is affected by CVE-2020-23194?
CVE-2020-23194 affects users of phpList version 3.5.4 and lower.
4
What does CVE-2020-23194 allow an attacker to do?
CVE-2020-23194 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
5
What feature is involved in CVE-2020-23194?
The vulnerability is found in the "Import Subscribers" feature of phpList.