CVE-2023-2998: Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
Other sources
In thorsten/phpmyfaq prior to 3.1.14, when admins create a FAQ News, they can pass xss to the "text of the record" section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-2998?
CVE-2023-2998 is a vulnerability that allows for cross-site scripting (XSS) attacks in the phpMyFAQ GitHub repository prior to version 3.1.14.
How does CVE-2023-2998 impact users?
CVE-2023-2998 allows malicious actors to inject and execute malicious scripts in the "text of the record" section when admins create a FAQ News on the phpMyFAQ platform.
What is the severity of CVE-2023-2998?
The severity of CVE-2023-2998 is medium, with a severity score of 6.1.
How can I fix CVE-2023-2998?
To fix CVE-2023-2998, users should update their phpMyFAQ installation to version 3.1.14 or higher.
Where can I find more information about CVE-2023-2998?
More information about CVE-2023-2998 can be found at the following references: [huntr.dev](https://huntr.dev/bounties/8282d78e-f399-4bf4-8403-f39103a31e78) and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-2998).