phpMyFAQ versions prior to 3.1.8 contain a reflected cross-site scripting vulnerability in the search functionality. The application fails to properly sanitize user input in the search parameter, allowing attackers to inject and execute malicious JavaScript code in the context of other users' browsers.
id: CVE-2022-3766
info:
name: phpMyFAQ < 3.1.8 - Cross-Site Scripting
author: ritikchaddha
se
...