Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq
CVE-2023-5319
8.3HIGH
What is CVE-2023-5319?
A stored cross-site scripting (XSS) vulnerability has been identified in phpMyFAQ versions prior to 3.1.18. This vulnerability allows attackers to inject malicious scripts into the application, which can then be executed in the context of another user's session. By exploiting this flaw, an attacker could potentially manipulate user interactions and steal sensitive information or perform unwanted actions on behalf of the user. It is crucial for users of phpMyFAQ to upgrade to version 3.1.18 or later to mitigate this security risk.
Affected Version(s)
thorsten/phpmyfaq < 3.1.18
