Description
phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
Remediation
References
Related Vulnerabilities
WordPress Plugin Video Lessons Manager-Best Video Course LMS Cross-Site Scripting (1.7.1)
WordPress Plugin Import and export users and customers Multiple Vulnerabilities (1.9.4.6)
Apache Tomcat 7PK - Errors Vulnerability (CVE-2016-8745)
WordPress Plugin All-in-One Event Calendar Multiple Cross-Site Scripting Vulnerabilities (1.5)