Cross-Site Scripting Vulnerability in phpMyFAQ
CVE-2017-14618
4.8MEDIUM
What is CVE-2017-14618?
An XSS vulnerability exists in the phpMyFAQ application through version 2.9.8, specifically within the inc/PMF/Faq.php file. This vulnerability allows malicious attackers to inject arbitrary web scripts or HTML via the 'Questions' field during the 'Add New FAQ' action. If exploited, this could result in unauthorized actions being performed on behalf of unsuspecting users or the compromise of their sensitive information.
