Miggo Logo

CVE-2024-27300: phpMyFAQ stored Cross-site Scripting at user email

5.5

CVSS Score
3.1

Basic Information

EPSS Score
0.5172%
Published
3/25/2024
Updated
4/4/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
phpmyfaq/phpmyfaqcomposer= 3.2.53.2.6

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Summ*ry T** `*m*il` *i*l* in p*pMy**Q's us*r *ontrol p*n*l p*** is vuln*r**l* to stor** XSS *tt**ks *u* to t** in***qu**y o* P*P's `*ILT*R_V*LI**T*_*M*IL` *un*tion, w*i** only v*li**t*s t** *m*il *orm*t, not its *ont*nt. T*is vuln*r**ility *n**l*

Reasoning

No *n*lysis *v*il**l*