CVE-2023-5316: Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq
Published Sep 30, 2023
·Updated
Cross-site Scripting (XSS) - DOM in GitHub repository thorsten/phpmyfaq prior to 3.1.18.
Affected Software
2 affected componentsFixes available
composer/thorsten/phpmyfaq<3.1.18
3.1.18
PhpMyFaq phpmyfaq<3.1.18
Remediation
Event History
Sep 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:31 AM
Frequently Asked Questions
1
What is CVE-2023-5316?
CVE-2023-5316 is a vulnerability in the GitHub repository thorsten/phpmyfaq prior to version 3.1.18 that allows for Cross-site Scripting (XSS) attacks through the Document Object Model (DOM).
2
How severe is CVE-2023-5316?
CVE-2023-5316 has a severity rating of critical, with a CVSS score of 6.1.
3
What software is affected by CVE-2023-5316?
The affected software includes the phpMyFAQ GitHub repository prior to version 3.1.18 and composer/thorsten/phpmyfaq package up to version 3.1.18.
4
How can I fix CVE-2023-5316?
To fix CVE-2023-5316, upgrade to version 3.1.18 of phpMyFAQ or the composer/thorsten/phpmyfaq package.
5
What is the CWE for CVE-2023-5316?
The CWE for CVE-2023-5316 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').