Arbitrary Web Script Injection in phpMyFAQ Faq.php

Arbitrary Web Script Injection in phpMyFAQ Faq.php

CVE-2017-14618 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

Learn more about our Web App Pen Testing.