phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
History

Thu, 08 May 2025 20:45:00 +0000

Type Values Removed Values Added
Description phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-08T00:00:00.000Z

Updated: 2025-05-08T20:34:07.068Z

Reserved: 2025-03-11T00:00:00.000Z

Link: CVE-2025-28074

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-05-08T21:15:50.200

Modified: 2025-05-08T21:15:50.200

Link: CVE-2025-28074

cve-icon Redhat

No data.