CVE-2023-0794: Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
Published Feb 12, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
Affected Software
2 affected componentsFixes available
PhpMyFaq phpmyfaq<3.1.11
composer/thorsten/phpmyfaq<3.1.11
3.1.11
Remediation
Event History
Feb 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-0794?
The severity of CVE-2023-0794 is high with a CVSS score of 5.4.
2
How can I fix the Cross-site Scripting (XSS) vulnerability in phpMyFAQ prior to version 3.1.11 (CVE-2023-0794)?
To fix the vulnerability, update phpMyFAQ to version 3.1.11 or newer.
3
Where can I find more information about the vulnerability CVE-2023-0794?
You can find more information about the vulnerability CVE-2023-0794 in the references provided: [1](https://github.com/thorsten/phpmyfaq/commit/edf0f6f90d4deaf46b4fd97ae92f16c1e10a2635) and [2](https://huntr.dev/bounties/949975f1-271d-46aa-85e5-1a013cdb5efb).
4
What is the CWE ID of CVE-2023-0794?
The CWE ID of CVE-2023-0794 is CWE-79.