phpList Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-35708 - Vulnerability Database
phpList Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2020-35708
High
Reference:
CVE-2020-35708
Title:
phpList Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the quotConfig - Import Administratorsquot page.