phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might affect other users. _Also, requires that adding new FAQs is allowed for guests and that the admin doesn't check the content of a newly added FAQ._ This vulnerability is fixed in 3.2.6.

Subscriptions

Vendors Products
Phpmyfaq Subscribe
Phpmyfaq Subscribe
Thorsten Subscribe
Phpmyfaq Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0812 phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficient validation on the `contentLink` parameter, it is possible for unauthenticated users to inject HTML code to the page which might affect other users. _Also, requires that adding new FAQs is allowed for guests and that the admin doesn't check the content of a newly added FAQ._ This vulnerability is fixed in 3.2.6.
Github GHSA Github GHSA GHSA-48vw-jpf8-hwqh phpMyFAQ Stored HTML Injection at contentLink
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 09 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Phpmyfaq
Phpmyfaq phpmyfaq
CPEs cpe:2.3:a:phpmyfaq:phpmyfaq:3.2.5:*:*:*:*:*:*:*
Vendors & Products Phpmyfaq
Phpmyfaq phpmyfaq

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T00:48:48.813Z

Reserved: 2024-03-04T14:19:14.059Z

Link: CVE-2024-28108

cve-icon Vulnrichment

Updated: 2024-08-01T18:42:05.001Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-25T19:15:58.700

Modified: 2025-01-09T17:00:12.770

Link: CVE-2024-28108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses