Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-28073 — Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary JavaScript execution. | Kitploit
Tools/GitHubGitHub/mlniumm/cve-2025-28073
Vulnerability AnalysisExploitationWeb Application ExploitationPhishingWeb Security
GitHubmlniumm/cve-2025-28073

CVE-2025-28073

Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary JavaScript execution.

View Repository
151 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-28073

[Suggested description] phpList 3.6.3 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject arbitrary JavaScript code by manipulating the id parameter, which is improperly sanitized.


[Vulnerability Type] Cross Site Scripting (XSS)


[Vendor of Product] phpList


[Affected Product Code Base] phpList - 3.6.15 (and possibly earlier versions)


[Affected Component] phpList /lists/dl.php, phpList 3.6.15 (and possibly earlier versions)


[Attack Type] Remote


[CVE Impact Other] Session Hijacking, Credential Theft, Phishing Attacks, Arbitrary JavaScript Execution


[Attack Vectors] This vulnerability is exploitable via a crafted URL containing malicious JavaScript code. A remote attacker can trick a victim into clicking a specially crafted link containing an XSS payload. When the victim accesses the vulnerable /lists/dl.php endpoint, the payload executes in their browser context. This may allow the attacker to steal session cookies, perform actions on behalf of the victim, or inject malicious content into the affected phpList instance.


[Reference]

https://github.com/phpList/phplist3

https://cve.mitre.org

https://www.exploit-db.com


[Discoverer] Pattharadech Soponrat

Download Tool