PT-2025-51967 · Phpmyfaq · Phpmyfaq

·

CVE-2023-53929

·

Published

2025-12-17

·

Updated

2025-12-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ version 3.1.12
Description The software contains a CSV injection flaw that permits authenticated users to inject malicious formulas into their profile names. An attacker can modify their user profile name with a payload such as 'calc|a!z|' to trigger code execution when an administrator exports user data as a CSV file.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the characters allowed in user profile names to prevent the injection of malicious formulas.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53929
GHSA-X2V3-9P22-W3X6

Affected Products

Phpmyfaq