CSV Injection Vulnerability in phpMyFAQ Admin Backend
CVE-2018-16651

7.2HIGH

Key Information:

Vendor

pHPMyFAQ

Status
Vendor
CVE Published:
7 September 2018

What is CVE-2018-16651?

The admin backend of phpMyFAQ, prior to version 2.9.11, is susceptible to CSV injection in its reporting functionality. When unauthorized users craft malicious CSV content, they can manipulate data upon export, leading to potential exposure of sensitive information. Proper validation and sanitization mechanisms should be implemented to prevent the execution of harmful scripts that may exploit this vulnerability.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.