Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2020-23214
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
0
Attacker Value
Unknown
CVE-2020-23208
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Send test" field under the "Start or continue campaign" module.
0
Attacker Value
Unknown
CVE-2020-23217
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
0
Attacker Value
Unknown
CVE-2020-23207
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
0
Attacker Value
Unknown
CVE-2020-23209
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "List Description" field under the "Edit A List" module.
0
Attacker Value
Unknown
CVE-2020-23361
Disclosure Date: January 27, 2021 (last updated November 28, 2024)
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
0