Stored Cross-Site Scripting Vulnerability in phpList by phpList Ltd.
CVE-2020-23207
5.4MEDIUM
What is CVE-2020-23207?
A stored cross-site scripting vulnerability exists in phpList version 3.5.3, which allows attackers to execute arbitrary scripts or HTML. This is achieved by injecting a malicious payload into the 'Edit Values' field within the 'Configure Attributes' module. If exploited, this vulnerability can lead to unauthorized actions on behalf of users and compromise sensitive information, making it essential for users to update their installations or apply recommended mitigations.
