Cross-Site Scripting Vulnerability in phpList by phpList
CVE-2025-28074

6.1MEDIUM

Key Information:

Vendor

phpList

Status
Vendor
CVE Published:
8 May 2025

What is CVE-2025-28074?

The phpList application prior to version 3.6.3 contains a vulnerability that allows for Cross-Site Scripting (XSS) due to insufficient input sanitization in the lt.php script. This exploitable flaw arises when the application dynamically references internal paths and processes untrusted user input without applying proper escaping techniques. An attacker can leverage this vulnerability to introduce malicious JavaScript code, potentially compromising the security of user sessions and exposing sensitive information.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.