CVE-2023-6889: Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
Published Dec 16, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
Affected Software
2 affected componentsFixes available
composer/thorsten/phpmyfaq<3.1.17
3.1.17
PhpMyFaq phpmyfaq<3.1.17
Remediation
Event History
Dec 16, 2023
CVE Published
08:57 AM
Data Sourced
08:57 AM
DescriptionSeverityWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6889?
CVE-2023-6889 is classified as a security vulnerability due to Cross-site Scripting (XSS) risks.
2
How do I fix CVE-2023-6889?
To fix CVE-2023-6889, upgrade to the version 3.1.17 or later of phpMyFAQ.
3
What software is affected by CVE-2023-6889?
CVE-2023-6889 affects phpMyFAQ versions prior to 3.1.17.
4
What type of vulnerability is CVE-2023-6889?
CVE-2023-6889 is a Stored Cross-site Scripting (XSS) vulnerability.
5
Is CVE-2023-6889 a critical vulnerability?
While CVE-2023-6889 poses significant risks due to XSS, its criticality depends on the specific deployment and exposure of the application.