Description
A stored cross site scripting (XSS) vulnerability in phplist 3.5.4 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "rule1" parameter under the "Bounce Rules" module.
Remediation
References
Related Vulnerabilities
Envoy Proxy Origin Validation Error Vulnerability (CVE-2020-15104)
WordPress Plugin RSS Includes Pages Cross-Site Scripting (3.6)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7925)
CakePHP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-8379)
WordPress Plugin WP Social Invitations Cross-Site Scripting (1.4.4.2)