CVE-2022-4407: Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
Published Dec 11, 2022
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<3.1.9
Remediation
Event History
Dec 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 16, 2025
Exploit Published
12:00 AM
Known Exploited
05:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-4407?
CVE-2022-4407 is classified as a medium severity vulnerability due to its potential for reflected Cross-site Scripting (XSS).
2
How do I fix CVE-2022-4407?
To fix CVE-2022-4407, upgrade phpMyFAQ to version 3.1.9 or later, which addresses this vulnerability.
3
What type of vulnerability is CVE-2022-4407?
CVE-2022-4407 is a Cross-site Scripting (XSS) vulnerability that is reflected.
4
Which versions of phpMyFAQ are affected by CVE-2022-4407?
CVE-2022-4407 affects all versions of phpMyFAQ prior to 3.1.9.
5
Can CVE-2022-4407 be exploited remotely?
Yes, CVE-2022-4407 can be exploited remotely since it involves reflected XSS, allowing attackers to execute scripts in the context of a user's browser.