phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers. This vulnerability is fixed in 3.2.6.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-25T18:41:58.260Z

Updated: 2024-08-02T00:48:49.468Z

Reserved: 2024-03-04T14:19:14.059Z

Link: CVE-2024-28106

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:49.468Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-25T19:15:58.263

Modified: 2024-03-26T12:55:05.010

Link: CVE-2024-28106

cve-icon Redhat

No data.