Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "Campaign" field under the "Send a campaign" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin Theme Editor Multiple Vulnerabilities (2.1)
WordPress Plugin Affiliate Power-Sales Tracking for Affiliate Marketers Cross-Site Scripting (2.2.0)
Jboss EAP Improper Input Validation Vulnerability (CVE-2010-3708)
WordPress Plugin Share Buttons by AddThis Cross-Site Request Forgery (5.3.5)
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3836)