Description
phpList before 3.5.4 allows XSS via /lists/admin/user.php and /lists/admin/users.php.
Remediation
References
Related Vulnerabilities
Atlassian Jira URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-39112)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-5406)
WordPress Plugin wp-football Multiple Cross-Site Scripting Vulnerabilities (1.1)
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-44967)