CVE-2024-28106

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 25, 2024
Updated: Jan 9, 2025
CWE ID 79

Summary

CVE-2024-28106 is a newly disclosed vulnerability affecting phpMyFAQ, an open-source FAQ web application for PHP 8.1 and above, and various databases including MySQL and PostgreSQL. An attacker can exploit this issue by manipulating the news parameter in a POST request, leading to the injection of malicious JavaScript code. Subsequently, upon visiting the compromised news page, the XSS (Cross-Site Scripting) payload is triggered, posing a serious security risk. The vulnerability has been addressed in phpMyFAQ version 3.2.6.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share