CVE-2024-28106
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating t
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating the news parameter in a POST request, an attacker can inject malicious JavaScript code. Upon browsing to the compromised news page, the XSS payload triggers.
This vulnerability is fixed in 3.2.6.
MEDIUM · CVSS 4.3
EPSS 0.00157
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0