← Zurück zur CVE-Suche

CVE-2026-46367

phpMyFAQ

Beschreibung

phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticated users to inject JavaScript via malformed URLs in comments. Attackers can craft URLs with unescaped quotes to inject event handlers, stealing admin session cookies and achieving full application takeover when visitors view affected FAQ pages.

CVSS 7.6EPSS 0.215%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-05-15 19:17:04
Betroffene Versionen
<4.1.2
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N