CVE-2023-6890: Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
Published Dec 16, 2023
·Updated
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.
Affected Software
2 affected componentsFixes available
composer/thorsten/phpmyfaq<3.1.17
3.1.17
PhpMyFaq phpmyfaq<3.1.17
Remediation
Event History
Dec 16, 2023
CVE Published
08:57 AM
Data Sourced
08:57 AM
DescriptionSeverityWeakness
Advisory Published
09:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-6890?
CVE-2023-6890 is categorized as a Cross-site Scripting (XSS) vulnerability, which can lead to significant security risks.
2
How do I fix CVE-2023-6890?
To remediate CVE-2023-6890, upgrade to phpMyFAQ version 3.1.17 or later.
3
What software is affected by CVE-2023-6890?
CVE-2023-6890 affects phpMyFAQ versions prior to 3.1.17.
4
What type of vulnerability is CVE-2023-6890?
CVE-2023-6890 is a stored Cross-site Scripting (XSS) vulnerability.
5
Can CVE-2023-6890 be exploited remotely?
Yes, CVE-2023-6890 can be exploited remotely, allowing attackers to execute scripts in the context of the user's session.