Lucene search

K
osvGoogleOSV:CVE-2020-23209
HistoryJul 01, 2021 - 9:15 p.m.

CVE-2020-23209

2021-07-0121:15:08
Google
osv.dev
7
phplist 3.5.3
stored xss
arbitrary web script execution
crafted payload
list description
edit a list
software

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

24.8%

A stored cross site scripting (XSS) vulnerability in phplist 3.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the “List Description” field under the “Edit A List” module.

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for OSV:CVE-2020-23209