CVE-2017-14618: XSS
Published Sep 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<=2.9.8
Event History
Sep 20, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14618?
CVE-2017-14618 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-14618?
To fix CVE-2017-14618, upgrade to phpMyFAQ version 2.9.9 or later where the vulnerability is patched.
3
Who is affected by CVE-2017-14618?
CVE-2017-14618 affects users of phpMyFAQ versions up to and including 2.9.8.
4
What type of attack can be executed through CVE-2017-14618?
An attacker can exploit CVE-2017-14618 to inject arbitrary web script or HTML into the Questions field.
5
When was CVE-2017-14618 discovered?
CVE-2017-14618 was publicly disclosed on October 19, 2017.