PT-2026-85493 · Phpmyfaq · Phpmyfaq
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.8
Description
A stored cross-site scripting issue exists where the
convertOldInternalLinks() function in FaqHelper calls html entity decode() on sanitized FAQ content. This process reverses the entity-encoding protection, allowing authenticated users with FAQ editing privileges to inject JavaScript payloads. These payloads execute in the browsers of all users who view the affected FAQ pages.Recommendations
Update to version 4.1.8 or later.
As a temporary mitigation, restrict FAQ editing privileges to only highly trusted users.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq