Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-0306: fix: added missing conversion to HTML entities · thorsten/phpMyFAQ@1815dae

Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.10.

CVE
#xss#git#php

@@ -28,6 +28,7 @@

use phpMyFAQ\Language;

use phpMyFAQ\LinkVerifier;

use phpMyFAQ\Search\SearchFactory;

use phpMyFAQ\Strings;

use phpMyFAQ\Visits;

if (!defined(‘IS_VALID_PHPMYFAQ’)) {

@@ -456,8 +457,9 @@ function verifyEntryURL_failure(XmlRequest)

</td>

<td>

<a href="?action=editentry&id=<?= $record[‘id’] ?>&lang=<?= $record[‘lang’] ?>"

title="<?= $PMF_LANG[‘ad_user_edit’] ?> '<?= str_replace('"’, '´’, $record[‘title’]) ?>’">

<?= $record[‘title’] ?>

title="<?= $PMF_LANG[‘ad_user_edit’] ?> '

<?= str_replace('"’, '´’, Strings::htmlentities($record[‘title’])) ?>’">

<?= Strings::htmlentities($record[‘title’]) ?>

</a>

<?php

if (isset($numCommentsByFaq[$record[‘id’]])) {

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907