CVE-2023-2428: Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
Published Apr 30, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.13.
Other sources
phpMyFAQ prior to version 3.1.13 has a stored cross site scripting vulnerability in name field in add question module. This allows an attacker to steal user cookies.
Affected Software
2 affected componentsFixes available
PhpMyFaq phpmyfaq<3.1.13
composer/thorsten/phpmyfaq<3.1.13
3.1.13
Remediation
Event History
Apr 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 AM
Data Sourced
via GitHub·03:30 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-2428.
2
What is the severity of CVE-2023-2428?
The severity of CVE-2023-2428 is medium (5.4).
3
What is the affected software for CVE-2023-2428?
The affected software for CVE-2023-2428 is phpMyFAQ prior to version 3.1.13.
4
What is the CWE ID associated with CVE-2023-2428?
The CWE ID associated with CVE-2023-2428 is CWE-79.
5
How can I fix CVE-2023-2428?
To fix CVE-2023-2428, upgrade to phpMyFAQ version 3.1.13 or later.