phpMyFAQ是Thorsten Rinne个人开发者的一个多语言、完全由数据库驱动的常见问题解答系统。 phpMyFAQ 3.2.4版本存在安全漏洞,该漏洞源于phpMyFAQphpmyfaqadminattachments.php中的文件名的不安全回显会导致允许在客户端执行 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-22208 | 6.5 MEDIUM | phpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes |
| CVE-2024-22202 | 5.7 MEDIUM | User Removal Page Allows Spoofing Of User Details |
No comments yet