Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Remediation
References
Related Vulnerabilities
CakePHP Improper Input Validation Vulnerability (CVE-2016-4793)
WordPress Plugin Duplicate Page Cross-Site Scripting (4.4.2)
WordPress Plugin Passster-Password Protection Security Bypass (3.5.5.8)
Oracle Database Server CVE-2008-2613 Vulnerability (CVE-2008-2613)
WordPress Plugin Light Post 'abspath' Parameter Remote File Include (1.4)