Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload in the "admin" parameter under the "Manage administrators" module.
Remediation
References
Related Vulnerabilities
OpenSSL Improper Certificate Validation Vulnerability (CVE-2023-0464)
Apache Tomcat Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1336)
Apache Tomcat Other Vulnerability (CVE-2001-0829)
FluxBB CVE-2011-3621 Vulnerability (CVE-2011-3621)
WordPress Plugin WP e-Commerce Shop Styling Local File Inclusion (2.9.1)