CVE-2017-14618
MEDIUMphpmyfaq < 2.9.8 - Cross-Site Scripting via Questions Field in Add New FAQ Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-14618. PoCs published by Ishaq Mohammed.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in phpMyFAQ 2.9.8 via the 'Questions' field in the 'Add New FAQ' action. The PoC involves injecting malicious JavaScript into the FAQ question, which executes when a user hovers over the link.
Description
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in phpMyFAQ 2.9.8 via the 'Questions' field in the 'Add New FAQ' action. The PoC involves injecting malicious JavaScript into the FAQ question, which executes when a user hovers over the link.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N