High severity7.2NVD Advisory· Published Dec 25, 2020· Updated Jun 17, 2026
CVE-2020-35708
CVE-2020-35708
Description
phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the "Config - Import Administrators" page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- tufangungor.github.io/exploit/2020/12/15/phplist-3.5.9-sql-injection.htmlnvdExploitThird Party Advisory
- sourceforge.net/projects/phplist/files/phplist/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.