PT-2024-2384 · Phpmyfaq · Phpmyfaq

Kevinnivekkevin

·

Published

2024-03-25

·

Updated

2025-01-09

·

CVE-2024-28106

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 3.2.6
Description The issue is related to the manipulation of the news parameter in a POST request, allowing an attacker to inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers. This enables an attacker to execute arbitrary client-side JavaScript within the context of another user's phpMyFAQ session.
Recommendations For versions prior to 3.2.6, update to version 3.2.6 to resolve the issue. As a temporary workaround, consider restricting access to the news page or disabling the ability to edit FAQ news until the update is applied. Avoid using the news parameter in POST requests to the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2024-02335
CVE-2024-28106
GHSA-6P68-36M6-392R

Affected Products

Phpmyfaq