PT-2023-17311 · Unknown · Thorsten/Phpmyfaq

Published

2023-04-05

·

Updated

2023-09-02

·

CVE-2023-1883

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions thorsten/phpmyfaq versions prior to 3.1.12
Description The issue concerns improper access control in the thorsten/phpmyfaq GitHub repository. Specifically, when FAQ News is marked as inactive in settings and comments are enabled, it allows comments to be posted on inactive FAQs.
Recommendations For versions prior to 3.1.12, update to version 3.1.12 to resolve the issue. As a temporary workaround, consider disabling comments on inactive FAQs until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2023-1883
GHSA-2WJP-W7G7-H63Q

Affected Products

Thorsten/Phpmyfaq