CVE-2012-3952

EUVD-2012-3896
Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
Affected Products (NVD)
VendorProductVersion
phplistphplist
𝑥
≤ 2.10.18
phplistphplist
2.6.5
phplistphplist
2.7.1
phplistphplist
2.7.2
phplistphplist
2.8.2
phplistphplist
2.8.7
phplistphplist
2.8.12
phplistphplist
2.10.1
phplistphplist
2.10.2
phplistphplist
2.10.3
phplistphplist
2.10.4
phplistphplist
2.10.5
phplistphplist
2.10.7
phplistphplist
2.10.8
phplistphplist
2.10.9
phplistphplist
2.10.10
phplistphplist
2.10.11
phplistphplist
2.10.12
phplistphplist
2.10.13
phplistphplist
2.10.14
phplistphplist
2.10.15
phplistphplist
2.10.16
phplistphplist
2.10.17
𝑥
= Vulnerable software versions