CVE-2023-4006: Improper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaq
Published Jul 31, 2023
·Updated
Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
Affected Software
2 affected componentsFixes available
composer/thorsten/phpmyfaq<3.1.16
3.1.16
PhpMyFaq phpmyfaq<3.1.16
Remediation
Event History
Jul 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-4006?
The severity of CVE-2023-4006 is critical with a CVSS score of 9.8.
2
What is the affected software version for CVE-2023-4006?
The affected software version for CVE-2023-4006 is up to (exclusive) version 3.1.16.
3
How can I fix CVE-2023-4006?
To fix CVE-2023-4006, update your GitHub repository thorsten/phpmyfaq to version 3.1.16.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-4006?
The Common Weakness Enumeration (CWE) for CVE-2023-4006 is CWE-1236.
5
Where can I find more information about CVE-2023-4006?
You can find more information about CVE-2023-4006 at the following references: - [Huntr](https://huntr.dev/bounties/36149a42-cbd5-445e-a371-e351c899b189) - [GitHub Commit](https://github.com/thorsten/phpmyfaq/commit/03946eca488724251eaed8d9d36fed92e6d8fd22) - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-4006)