First published: Mon Jul 31 2023(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.16.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Phpmyfaq Phpmyfaq | <3.1.16 | |
composer/thorsten/phpmyfaq | <3.1.16 | 3.1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-4007 is high with a severity value of 8.8.
CVE-2023-4007 is a cross-site scripting (XSS) vulnerability that allows malicious script injection in the GitHub repository thorsten/phpmyfaq prior to version 3.1.16, potentially leading to unauthorized access or data manipulation.
To fix CVE-2023-4007 in the GitHub repository thorsten/phpmyfaq, update to version 3.1.16 or newer.
The Common Vulnerabilities and Exposures (CVE) ID of this vulnerability is CVE-2023-4007.
Yes, you can find additional information about CVE-2023-4007 in the following references: [Reference 1](https://github.com/thorsten/phpmyfaq/commit/40eb9685198128908e83c2bef4c228751fd43a0e), [Reference 2](https://huntr.dev/bounties/e891dcbc-2092-49d3-9518-23e37187a5ea), [Reference 3](https://nvd.nist.gov/vuln/detail/CVE-2023-4007).