First published: Wed Sep 20 2017(Updated: )
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | <=2.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14618 is classified as a high severity cross-site scripting (XSS) vulnerability.
To fix CVE-2017-14618, upgrade to phpMyFAQ version 2.9.9 or later where the vulnerability is patched.
CVE-2017-14618 affects users of phpMyFAQ versions up to and including 2.9.8.
An attacker can exploit CVE-2017-14618 to inject arbitrary web script or HTML into the Questions field.
CVE-2017-14618 was publicly disclosed on October 19, 2017.