First published: Sat Sep 30 2023(Updated: )
Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.18.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
composer/thorsten/phpmyfaq | <3.1.18 | 3.1.18 |
Phpmyfaq Phpmyfaq | <3.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5227 is a vulnerability that allows for unrestricted upload of files with dangerous types in the thorsten/phpmyfaq GitHub repository prior to version 3.1.18.
CVE-2023-5227 has a severity rating of 9.8, which is classified as critical.
The Phpmyfaq Phpmyfaq software prior to version 3.1.18 and the thorsten/phpmyfaq package with versions up to exclusive 3.1.18 are affected by CVE-2023-5227.
To fix the CVE-2023-5227 vulnerability, ensure you are using version 3.1.18 or later of Phpmyfaq Phpmyfaq or the thorsten/phpmyfaq package.
You can find more information about CVE-2023-5227 at the following references: [GitHub commit](https://github.com/thorsten/phpmyfaq/commit/abf52487422ce47195c8a80bd904a7af39f60297), [huntr.dev](https://huntr.dev/bounties/a335c013-db75-4120-872c-42059c7100e8), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-5227).