Description
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
Remediation
References
Related Vulnerabilities
MediaWiki Other Vulnerability (CVE-2005-4031)
Oracle Application Server Other Vulnerability (CVE-2002-1630)
WordPress Plugin Login/Signup Popup (Inline Form + Woocommerce) Cross-Site Request Forgery (2.2)
WordPress Plugin Kama Click Counter Cross-Site Scripting (3.4.9)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery Cross-Site Scripting (1.2.12)