CVE-2017-14619: XSS
Published Sep 20, 2017
·Updated
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<=2.9.8
Remediation
Event History
Sep 20, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14619?
CVE-2017-14619 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-14619?
To fix CVE-2017-14619, upgrade phpMyFAQ to version 2.9.9 or later, where the vulnerability has been addressed.
3
What is affected by CVE-2017-14619?
CVE-2017-14619 affects phpMyFAQ versions up to and including 2.9.8.
4
What type of vulnerability is CVE-2017-14619?
CVE-2017-14619 is a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2017-14619?
Remote attackers can exploit CVE-2017-14619 to inject arbitrary web scripts or HTML.