CVE-2024-28106
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 25, 2024
Updated: Jan 9, 2025
CWE ID 79
Summary
CVE-2024-28106 is a newly disclosed vulnerability affecting phpMyFAQ, an open-source FAQ web application for PHP 8.1 and above, and various databases including MySQL and PostgreSQL. An attacker can exploit this issue by manipulating the news parameter in a POST request, leading to the injection of malicious JavaScript code. Subsequently, upon visiting the compromised news page, the XSS (Cross-Site Scripting) payload is triggered, posing a serious security risk. The vulnerability has been addressed in phpMyFAQ version 3.2.6.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.