Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin Transposh WordPress Translation Multiple Vulnerabilities (1.0.8.1)
PHP Improper Preservation of Permissions Vulnerability (CVE-2020-7063)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0682)
WordPress Plugin Citizen Space Cross-Site Scripting (1.1)
WordPress Plugin CM Ad Changer Multiple Cross-Site Scripting Vulnerabilities (1.7.2)