Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown

CVE-2020-23208

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.
Attacker Value
Unknown

CVE-2020-23217

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
Attacker Value
Unknown

CVE-2020-23207

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
Attacker Value
Unknown

CVE-2020-23209

Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.
Attacker Value
Unknown

CVE-2020-23361

Disclosure Date: January 27, 2021 (last updated November 28, 2024)
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
Attacker Value
Unknown

CVE-2021-3188

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Attacker Value
Unknown

CVE-2020-35708

Disclosure Date: December 25, 2020 (last updated February 22, 2025)
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
Attacker Value
Unknown

CVE-2020-15073

Disclosure Date: July 08, 2020 (last updated February 21, 2025)
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
Attacker Value
Unknown

CVE-2020-15072

Disclosure Date: July 08, 2020 (last updated February 21, 2025)
An issue was discovered in phpList through 3.5.4. An error-based SQL Injection vulnerability exists via the Import Administrators section.
Attacker Value
Unknown

CVE-2020-13827

Disclosure Date: June 04, 2020 (last updated February 21, 2025)
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.