CVE-2024-29179
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Mar 25, 2024
Updated: Jan 9, 2025
CWE ID 79
Summary
CVE-2024-29179 is a vulnerability affecting phpMyFAQ, an open-source FAQ web application. The issue permits admin users to upload JavaScript files without an extension, which the application incorrectly renders as HTML. This misconfiguration leads to Cross-Site Scripting (XSS) attacks, allowing malicious code execution on vulnerable websites. Attackers can exploit this vulnerability to steal user data or perform unauthorized actions. It is essential for phpMyFAQ users to apply the necessary security patches or upgrades to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.