← Back to CVE List

CVE-2020-22249

Published: 2021-07-06T20:15Z
Last Modified: 2024-11-21T05:13Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution > MITRE Terms of Use apply – see LICENSE‑MITRE.txt