Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown
CVE-2020-22249
Disclosure Date: July 06, 2021 (last updated February 22, 2025)
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution
0
Attacker Value
Unknown
CVE-2020-36399
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
0
Attacker Value
Unknown
CVE-2020-23192
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload in the "admin" parameter under the "Manage administrators" module.
0
Attacker Value
Unknown
CVE-2020-23190
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in the "Import emails" module in phplist 3.5.4 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2020-23194
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2020-36398
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
0
Attacker Value
Unknown
CVE-2020-23214
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
0
Attacker Value
Unknown
CVE-2020-23208
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.
0
Attacker Value
Unknown
CVE-2020-23217
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
0
Attacker Value
Unknown
CVE-2020-23207
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
0