Description
phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.
Remediation
References
Related Vulnerabilities
PHP socket_iovec_alloc() integer overflow
WordPress Plugin Thank You Counter Button Multiple Cross-Site Scripting Vulnerabilities (1.8.7)
phpMyAdmin Other Vulnerability (CVE-2005-0459)
WordPress Plugin Product Addons & Fields for WooCommerce Cross-Site Scripting (32.0.6)
PHP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-19520)