Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Edit Values" field under the "Configure Attributes" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin iThemes Security (formerly Better WP Security) Information Disclosure (5.1.1)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5492)
WordPress Plugin IP Geo Block Security Bypass (2.2.2)
MySQL Resource Management Errors Vulnerability (CVE-2010-3836)
Jboss EAP Incorrect Authorization Vulnerability (CVE-2019-14843)