Security Advisory 2023-08-27

XSS and CSV injection vulnerabilities in phpMyFAQ

Issued on:
2023-08-27
Software:
phpMyFAQ <= 3.1.16
Risk:
Medium
Platforms:
all

The phpMyFAQ Team has learned of multiple security issues that'd been discovered in phpMyFAQ 3.1.16 and

earlier. phpMyFAQ contains cross-site scripting (XSS) vulnerabilities.

Description

phpMyFAQ doesn't implement sufficient checks to avoid XSS when adding malicious content into tags and FAQs.

Solution

The phpMyFAQ Team has released the new phpMyFAQ version 3.1.17, which fixes these vulnerabilities. All

users of affected phpMyFAQ versions are encouraged to upgrade as soon as possible to this latest version.

Workaround

There's no workaround except installing phpMyFAQ 3.1.17.

References

Thanks

The phpMyFAQ team would like to thank @ahmedvienna for the responsible disclosures of these vulnerabilities.