Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3j93-7rf7-p7m6: thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS)

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to stored cross-site scripting (XSS) because it fails to sanitize user input. This has been fixed in 3.1.12.

ghsa
#xss#git#php

thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS)

High severity GitHub Reviewed Published Apr 5, 2023 to the GitHub Advisory Database • Updated Apr 5, 2023

Related news

CVE-2023-1758: fix: added missing conversion to HTML entities · thorsten/phpMyFAQ@f3380f4

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository thorsten/phpmyfaq prior to 3.1.12.