First published: Fri Jan 27 2023(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.0-beta.2.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Phpmyfaq Phpmyfaq | <=3.1.14 | |
Phpmyfaq Phpmyfaq | =3.2.0-alpha | |
Phpmyfaq Phpmyfaq | =3.2.0-beta | |
IBM Cloud Pak for Business Automation | <=V22.0.2 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF016 | |
IBM Cloud Pak for Business Automation | <=V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixesV21.0.1 - V21.0.1-IF007 and later fixesV20.0.1 - V20.0.3 and later fixesV19.0.1 - V19.0.3 and later fixesV18.0.0 - V18.0.2 and later fixes | |
composer/thorsten/phpmyfaq | <3.2.0-beta.2 | 3.2.0-beta.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3469 is a vulnerability in IBM ICP4A - Automation Decision Services that allows for cross-site scripting (XSS) attacks.
The severity of CVE-2023-3469 is medium, with a CVSS score of 4.8.
The affected versions include IBM Cloud Pak for Business Automation V22.0.2, V21.0.3 - V21.0.3-IF016, V22.0.1 - V22.0.1-IF006 and later fixes, V21.0.2 - V21.0.2-IF012 and later fixes, V21.0.1 - V21.0.1-IF007 and later fixes, V20.0.1 - V20.0.3 and later fixes, V19.0.1 - V19.0.3 and later fixes, and V18.0.0 - V18.0.2 and later fixes, as well as Phpmyfaq versions up to 3.1.14, 3.2.0-alpha, and 3.2.0-beta.
As a user, you can exploit the vulnerability in CVE-2023-3469 by injecting malicious scripts into web pages on the affected system, which can then be executed by other users who access the pages.
To fix the vulnerability in CVE-2023-3469, it is recommended to update to a version of IBM Cloud Pak for Business Automation that includes the necessary fixes, or update to a version of Phpmyfaq that is not affected by the vulnerability.