CVE-2020-35708

Publication date

2020-12-25 05:24:04

Family

mitre

State

PUBLISHED

Description

phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.