PT-2026-41369 · Phpmyfaq · Phpmyfaq
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.2
Description
A stored cross-site scripting issue exists in the
parseUrl() function of the Utils class. Authenticated users can inject JavaScript by submitting malformed URLs in comments. By using unescaped quotes to inject event handlers, attackers can steal administrator session cookies, potentially leading to a full application takeover when users view the affected FAQ pages.Recommendations
Update to version 4.1.2 or later.
As a temporary workaround, restrict the ability of users to post URLs in comments until the update is applied.
Exploit
Fix
XSS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq