Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
Remediation
References
Related Vulnerabilities
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8166)
WordPress Plugin Social Auto Poster-WordPress Scheduler & Marketing Security Bypass (5.3.14)
IBM RTC Improper Input Validation Vulnerability (CVE-2015-1928)
WordPress Plugin WP Cost Estimation & Payment Forms Builder Directory Traversal (9.659)
Oracle Database Server CVE-2006-5340 Vulnerability (CVE-2006-5340)