Description
A stored cross site scripting (XSS) vulnerability in the "Import Subscribers" feature in phplist 3.5.4 and below allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Remediation
References
Related Vulnerabilities
WordPress Plugin Feed Them Social-for Twitter feed, Youtube and more Cross-Site Scripting (1.6.9)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9853)
Oracle Database Server CVE-2009-1979 Vulnerability (CVE-2009-1979)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2101)
Joomla Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-12765)