Cross-Site Scripting Vulnerability in phpList by phpList
CVE-2020-12639
6.1MEDIUM
What is CVE-2020-12639?
A cross-site scripting vulnerability exists in phpList versions prior to 3.5.3, allowing an attacker to execute arbitrary scripts in the context of the user's browser. This could lead to privilege elevation and unauthorized actions within the application. The flaw is located in the lists/admin/template.php file, where improper input validation can be exploited. It is strongly recommended to update to phpList version 3.5.3 or later to mitigate this vulnerability.
