VulnerabilityModified
CVE-2020-15073
An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document.
MEDIUM 5.4EPSS 0.75%
Does this matter?
Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in phpList through 3.5.4. An XSS vulnerability occurs within the Import Administrators section via upload of an edited text document. This also affects the Subscriber Lists section.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.75% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- phplist/phplist
- Source
- cve@mitre.org
References
- https://blog.telspace.co.za/2020/07/phplist-cve-2020-15072-cve-2020-15073.htmlExploit, Third Party Advisory
- https://discuss.phplist.org/t/phplist-3-5-5-has-been-released/6377Release Notes, Vendor Advisory
- https://www.phplist.org/newslist/phplist-3-5-5-release-notes/Release Notes, Vendor Advisory
- https://blog.telspace.co.za/2020/07/phplist-cve-2020-15072-cve-2020-15073.htmlExploit, Third Party Advisory
- https://discuss.phplist.org/t/phplist-3-5-5-has-been-released/6377Release Notes, Vendor Advisory
- https://www.phplist.org/newslist/phplist-3-5-5-release-notes/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.