Stored Cross Site Scripting in phpList Affects User Data Security
CVE-2020-23194

5.4MEDIUM

Key Information:

Vendor

PHPlist

Status
Vendor
CVE Published:
2 July 2021

What is CVE-2020-23194?

A stored cross site scripting vulnerability exists in the Import Subscribers feature of phpList, versions 3.5.4 and earlier. This flaw allows attackers with authenticated access to inject malicious scripts or HTML into the web application, potentially compromising user data and executing unwanted actions on the client side.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.