Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP e-Commerce Shop Styling Local File Inclusion (2.9.1)
WordPress Plugin Visual Composer:Page Builder for WordPress Local File Inclusion (5.1)
WordPress Plugin Advanced Shipment Tracking for WooCommerce Security Bypass (3.2.6)
Plone CMS Improper Input Validation Vulnerability (CVE-2013-4195)