phpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/phpList/phplist3 | product |
https://github.com/mLniumm/CVE-2025-28073 | third party advisory |
https://github.com/phpList/phplist3/compare/v3.6.14...v3.6.15 | product |
https://www.phplist.org/newslist/phplist-3-6-15-release-notes/ | release notes |