phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://github.com/mLniumm/CVE-2025-28074 | Third Party Advisory |
https://github.com/phpList/phplist3/blob/main/public_html/lists/lt.php | Product |
https://github.com/phpList/phplist3/compare/v3.6.14...v3.6.15 | Product |
https://www.phplist.org/newslist/phplist-3-6-15-release-notes/ | Release Notes |
Configurations
History
16 Jun 2025, 18:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Phplist phplist
Phplist |
|
CPE | cpe:2.3:a:phplist:phplist:*:*:*:*:*:*:*:* | |
References | () https://www.phplist.org/newslist/phplist-3-6-15-release-notes/ - Release Notes | |
References | () https://github.com/mLniumm/CVE-2025-28074 - Third Party Advisory | |
References | () https://github.com/phpList/phplist3/compare/v3.6.14...v3.6.15 - Product | |
References | () https://github.com/phpList/phplist3/blob/main/public_html/lists/lt.php - Product |
07 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | phpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is exploitable when the application dynamically references internal paths and processes untrusted input without escaping, allowing an attacker to inject malicious JavaScript. |
08 May 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-08 21:15
Updated : 2025-06-16 18:39
NVD link : CVE-2025-28074
Mitre link : CVE-2025-28074
JSON object : View
Products Affected
phplist
- phplist
CWE
No CWE.