PT-2024-2384 · Phpmyfaq · Phpmyfaq
Kevinnivekkevin
·
Published
2024-03-25
·
Updated
2025-01-09
·
CVE-2024-28106
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 3.2.6
Description
The issue is related to the manipulation of the
news parameter in a POST request, allowing an attacker to inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers. This enables an attacker to execute arbitrary client-side JavaScript within the context of another user's phpMyFAQ session.Recommendations
For versions prior to 3.2.6, update to version 3.2.6 to resolve the issue. As a temporary workaround, consider restricting access to the news page or disabling the ability to edit FAQ news until the update is applied. Avoid using the
news parameter in POST requests to the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq