CVE-2024-24574

MEDIUM

phpMyFAQ < 3.2.5 - Cross-Site Scripting via Unsafe Filename Echo in Attachments Admin

Title source: llm
STIX 2.1

Description

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of filename in phpMyFAQ\phpmyfaq\admin\attachments.php leads to allowed execution of JavaScript code in client side (XSS). This vulnerability has been patched in version 3.2.5.

Scores

CVSS v3 6.5
EPSS 0.0088
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (2)
phpmyfaq/phpmyfaq < 3.2.5
phpmyfaq/phpmyfaq 0 - 3.2.5Packagist
Published Feb 05, 2024
Tracked Since Feb 18, 2026