First published: Wed May 31 2023(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Phpmyfaq Phpmyfaq | <3.1.14 | |
composer/thorsten/phpmyfaq | <3.1.14 | 3.1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2998 is a vulnerability that allows for cross-site scripting (XSS) attacks in the phpMyFAQ GitHub repository prior to version 3.1.14.
CVE-2023-2998 allows malicious actors to inject and execute malicious scripts in the "text of the record" section when admins create a FAQ News on the phpMyFAQ platform.
The severity of CVE-2023-2998 is medium, with a severity score of 6.1.
To fix CVE-2023-2998, users should update their phpMyFAQ installation to version 3.1.14 or higher.
More information about CVE-2023-2998 can be found at the following references: [huntr.dev](https://huntr.dev/bounties/8282d78e-f399-4bf4-8403-f39103a31e78) and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-2998).