Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5202
HistorySep 29, 2017 - 10:01 a.m.

Cross-site Scripting (XSS)

2017-09-2910:01:26
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.006

Percentile

79.3%

phpMyFAQ is vulnerable to cross-site scripting (XSS) attacks. The library does not escape the Title of your FAQ field in the Configuration module, allowing a malicious user to inject and execute arbitrary web script.