Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46085
HistoryMar 29, 2024 - 9:23 a.m.

Cross-site Scripting (XSS)

2024-03-2909:23:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
cross-site scripting
phpmyfaq
php
filter_validate_email
javascript
security vulnerability
client-side

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

15.5%

phpmyfaq/phpmyfaq is vulnerable to Cross-site Scripting (XSS). The vulnerability is caused due to the inadequacy of PHP’s FILTER_VALIDATE_EMAIL function, which only validates email format but not its content. This allows an attacker to execute arbitrary client-side JavaScript within the context of another user’s phpMyFAQ session.

CVSS3

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

15.5%