Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
Remediation
References
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2043)
OpenSSL Missing Encryption of Sensitive Data Vulnerability (CVE-2019-1547)
WordPress Plugin Custom Searchable Data Entry System Security Bypass (1.7.1)
WordPress Plugin Gravity Forms SQL Injection (1.9.3.5)
WordPress Plugin Slideshow Gallery LITE Cross-Site Scripting (1.7.3)