{"id":"CVE-2020-35708","details":"phpList 3.5.9 allows SQL injection by admins who provide a crafted fourth line of a file to the \"Config - Import Administrators\" page.","aliases":["BIT-phplist-2020-35708"],"modified":"2026-07-08T20:42:45.518410Z","published":"2020-12-25T06:15:14.330Z","references":[{"type":"ADVISORY","url":"https://sourceforge.net/projects/phplist/files/phplist/"},{"type":"EVIDENCE","url":"https://tufangungor.github.io/exploit/2020/12/15/phplist-3.5.9-sql-injection.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/phplist/phplist3","events":[{"introduced":"0e8e0d64f873c71f0cc551b58a820da934e9c5f8"},{"last_affected":"0e8e0d64f873c71f0cc551b58a820da934e9c5f8"}],"database_specific":{"extracted_events":[{"introduced":"3.5.9"},{"last_affected":"3.5.9"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:phplist:phplist:3.5.9:*:*:*:*:*:*:*"}}],"versions":["3.5.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35708.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}