Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Configure categories" field under the "Categorise Lists" module.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-4274 Vulnerability (CVE-2014-4274)
WordPress Plugin Contact Form 7 Style Cross-Site Request Forgery (3.1.9)
WordPress 4.4.x Multiple Vulnerabilities (4.4 - 4.4.29)
WordPress Plugin Mobile Events Manager CSV Injection (1.4.7)
b2evolution Improper Input Validation Vulnerability (CVE-2017-1000423)