Stored Cross-Site Scripting Vulnerability in phpList by phpList Ltd.
CVE-2020-23207

5.4MEDIUM

Key Information:

Vendor

PHPlist

Status
Vendor
CVE Published:
1 July 2021

What is CVE-2020-23207?

A stored cross-site scripting vulnerability exists in phpList version 3.5.3, which allows attackers to execute arbitrary scripts or HTML. This is achieved by injecting a malicious payload into the 'Edit Values' field within the 'Configure Attributes' module. If exploited, this vulnerability can lead to unauthorized actions on behalf of users and compromise sensitive information, making it essential for users to update their installations or apply recommended mitigations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.