Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq
CVE-2023-5316
9.1CRITICAL
What is CVE-2023-5316?
This vulnerability within phpMyFAQ allows attackers to exploit Cross-site Scripting (XSS) through DOM manipulation. Attackers can inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions, data theft, and compromised user sessions. Users are urged to update to version 3.1.18 or higher to mitigate these risks.
Affected Version(s)
thorsten/phpmyfaq < 3.1.18
