Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45347
HistoryFeb 06, 2024 - 5:22 a.m.

Cross Site Scripting (XSS)

2024-02-0605:22:48
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
cross site scripting
phpmyfaq
vulnerability
filename sanitization
javascript
client side

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

29.4%

phpmyfaq/phpmyfaq is vulnerable to Cross Site Scripting (XSS). The vulnerability is due to improper filename sanitization within phpMyFAQ\phpmyfaq\admin\attachments.php, allowing an attacker to execute arbitrary JavaScript code in the client side resulting in XSS.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

29.4%