CVE-2023-0314: Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
Published Jan 15, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.10.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<3.1.10
Remediation
Event History
Jan 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0314?
The severity of CVE-2023-0314 is medium with a CVSS score of 6.1.
2
How does CVE-2023-0314 affect the phpMyFAQ software?
CVE-2023-0314 affects the phpMyFAQ software versions prior to 3.1.10.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-0314?
The CWE ID for CVE-2023-0314 is CWE-79.
4
How can I fix the XSS vulnerability in phpMyFAQ?
To fix the XSS vulnerability in phpMyFAQ, update to version 3.1.10 or later.
5
Where can I find more information about CVE-2023-0314?
You can find more information about CVE-2023-0314 at the following references: - [GitHub commit](https://github.com/thorsten/phpmyfaq/commit/3872e7eac2ddeac182fc1335cc312d1392d56f98) - [Huntr bounty page](https://huntr.dev/bounties/eac0a9d7-9721-4191-bef3-d43b0df59c67)