Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1nZjM0LWhoNXItZjc0aM4AAxkK
Cross-site Scripting in thorsten/phpmyfaq
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
Permalink: https://github.com/advisories/GHSA-gf34-hh5r-f74hJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZjM0LWhoNXItZjc0aM4AAxkK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 4 months ago
Updated: 3 months ago
CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-gf34-hh5r-f74h, CVE-2023-0794
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-0794
- https://github.com/thorsten/phpmyfaq/commit/edf0f6f90d4deaf46b4fd97ae92f16c1e10a2635
- https://huntr.dev/bounties/949975f1-271d-46aa-85e5-1a013cdb5efb
- https://github.com/advisories/GHSA-gf34-hh5r-f74h
Affected Packages
packagist:thorsten/phpmyfaq
Versions: < 3.1.11Fixed in: 3.1.11