CVE-2023-5863: Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
Published Oct 31, 2023
·Updated
Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
Affected Software
2 affected componentsFixes available
composer/thorsten/phpmyfaq<3.2.2
3.2.2
PhpMyFaq phpmyfaq<3.2.2
Remediation
Event History
Oct 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:31 AM
Frequently Asked Questions
1
What is CVE-2023-5863?
CVE-2023-5863 is a vulnerability that allows for cross-site scripting (XSS) attacks in the thorsten/phpmyfaq GitHub repository prior to version 3.2.2.
2
How severe is CVE-2023-5863?
CVE-2023-5863 has a severity rating of high (7.4).
3
What is the affected software for CVE-2023-5863?
The affected software for CVE-2023-5863 is the thorsten/phpmyfaq GitHub repository version up to 3.2.2.
4
How can I fix CVE-2023-5863?
To fix CVE-2023-5863, you need to update your thorsten/phpmyfaq repository to version 3.2.2 or later.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-5863?
The Common Weakness Enumeration (CWE) for CVE-2023-5863 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').