CVE-2018-16651: Critical severity phpmyfaq vulnerability
Published Sep 7, 2018
·Updated
The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<2.9.11
Event History
Sep 7, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16651?
CVE-2018-16651 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-16651?
To fix CVE-2018-16651, upgrade phpMyFAQ to version 2.9.11 or later.
3
What type of injection is associated with CVE-2018-16651?
CVE-2018-16651 is associated with CSV injection in reports.
4
Which versions of phpMyFAQ are affected by CVE-2018-16651?
CVE-2018-16651 affects all versions of phpMyFAQ before 2.9.11.
5
What is the impact of CVE-2018-16651 on phpMyFAQ users?
The impact of CVE-2018-16651 allows an attacker to perform potentially malicious actions through crafted CSV input.