Reflected Cross-Site Scripting Vulnerability in phpList by phpList
CVE-2025-28073
6.1MEDIUM
What is CVE-2025-28073?
phpList version 3.6.3 is susceptible to a reflected cross-site scripting vulnerability through the /lists/dl.php endpoint. By manipulating the 'id' parameter, an attacker can inject arbitrary JavaScript code, which is not adequately sanitized. This vulnerability poses a risk as it may lead to unauthorized actions or steal sensitive information from users interacting with compromised pages.
