CVE-2017-15727: XSS
Published Oct 21, 2017
·Updated
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<=2.9.8
Remediation
Event History
Oct 21, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15727?
CVE-2017-15727 has been assigned a medium severity level due to its risk of stored Cross-site Scripting (XSS).
2
How do I fix CVE-2017-15727?
To fix CVE-2017-15727, upgrade phpMyFAQ to version 2.9.9 or later where the vulnerability has been addressed.
3
What types of systems are affected by CVE-2017-15727?
CVE-2017-15727 affects phpMyFAQ versions up to and including 2.9.8.
4
What can attackers achieve by exploiting CVE-2017-15727?
By exploiting CVE-2017-15727, attackers can execute malicious scripts in the context of the user's session.
5
Is user input a target in CVE-2017-15727?
Yes, CVE-2017-15727 targets user input through HTML attachments that may lead to stored XSS attacks.