Improper Neutralization of Formula Elements in a CSV File in thorsten/phpmyfaq
CVE-2023-4006
8.8HIGH
What is CVE-2023-4006?
The vulnerability affects phpMyFAQ prior to version 3.1.16 and arises due to improper handling of formula elements within CSV files. This issue can potentially lead to arbitrary code execution when a CSV file is opened in spreadsheet applications, as malicious formulas may be executed. It is crucial for users of affected versions to update to the latest release to mitigate this risk. For more details, refer to the recent commits and bug bounty discussions.
Affected Version(s)
thorsten/phpmyfaq < 3.1.16
