First published: Thu Jul 01 2021(Updated: )
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpList | =3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability identifier for the stored cross site scripting (XSS) vulnerability in phplist 3.5.3 is CVE-2020-23208.
The severity of CVE-2020-23208 is medium with a CVSS score of 5.4.
The stored cross site scripting (XSS) vulnerability in phplist 3.5.3 occurs when attackers enter a crafted payload into the "Send test" field under the "Start or continue campaign" module.
Attackers can execute arbitrary web scripts or HTML with the stored cross site scripting (XSS) vulnerability in phplist 3.5.3.
To mitigate the stored cross site scripting (XSS) vulnerability in phplist 3.5.3, update to a version that has the vulnerability fixed or apply the available patch.