Looking for the vulnerability index of Invicti's legacy products?
phpList Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12639) - Vulnerability Database

phpList Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12639)

Description

phpList before 3.5.3 allows XSS, with resultant privilege elevation, via lists/admin/template.php.

References

Related Vulnerabilities