CVE-2023-0787: Cross-site Scripting (XSS) - Generic in thorsten/phpmyfaq
Published Feb 12, 2023
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
Affected Software
1 affected component
PhpMyFaq phpmyfaq<3.1.11
Remediation
Event History
Feb 12, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-0787?
CVE-2023-0787 is a vulnerability in the GitHub repository thorsten/phpmyfaq prior to version 3.1.11 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2023-0787?
CVE-2023-0787 has a severity rating of high, with a severity value of 5.4.
3
How is phpMyFAQ affected by CVE-2023-0787?
phpMyFAQ versions prior to 3.1.11 are affected by CVE-2023-0787.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-0787?
CVE-2023-0787 is associated with CWE-79, which is a weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2023-0787?
To fix CVE-2023-0787, you should update your phpMyFAQ installation to version 3.1.11 or newer.