phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phplist
Phplist phplist |
|
CPEs | cpe:2.3:a:phplist:phplist:*:*:*:*:*:*:*:* | |
Vendors & Products |
Phplist
Phplist phplist |
Sat, 07 Jun 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. |
References |
|
Mon, 12 May 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Thu, 08 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | phpList prior to 3.6.3 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-05-08T00:00:00.000Z
Updated: 2025-06-07T14:42:05.947Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28074

Updated: 2025-05-12T22:05:51.272Z

Status : Analyzed
Published: 2025-05-08T21:15:50.200
Modified: 2025-06-16T18:39:00.380
Link: CVE-2025-28074

No data.