Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Add a list" field under the "Import Emails" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin Patreon WordPress Multiple Cross-Site Scripting Vulnerabilities (1.7.1)
datatables Cross-site Scripting (XSS) Vulnerability (CVE-2015-6584)
WordPress Plugin 10Web Map Builder for Google Maps Cross-Site Scripting (1.0.71)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-4279)