Cross-Site Request Forgery Vulnerability in phpMyFAQ by Thorsten
CVE-2017-15729

8.8HIGH

Key Information:

Vendor

pHPMyFAQ

Status
Vendor
CVE Published:
22 October 2017

What is CVE-2017-15729?

A vulnerability exists in phpMyFAQ prior to version 2.9.9 that enables an attacker to exploit Cross-Site Request Forgery (CSRF) techniques to alter content in the application, specifically allowing unauthorized users to add glossary entries. This demonstrates how user credentials can be misused if proper security measures are not in place.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.