Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Smart Coupons Security Bypass (4.6.0)
WordPress Plugin Login with Azure (Azure SSO) Cross-Site Scripting (1.4.4)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.15)
WordPress Plugin Zingiri Web Shop Multiple Cross-Site Scripting Vulnerabilities (2.4.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-0792)