VDB
Sign up
HIGH8.4

GHSA-6rj8-9cm9-6gff

phpMyFAQ vulnerable to Cross-site Scripting

Quick fix

GHSA-6rj8-9cm9-6gff — thorsten/phpmyfaq: upgrade to the fixed version with the command below.

composer require thorsten/phpmyfaq:^3.2.0-alpha

Details

phpMyFAQ versions 3.1.7 and prior are vulnerable to stored cross-site scripting (XSS). A patch is available on the `main` branch of the repository and anticipated to be part of version 3.2.0-alpha.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/thorsten/phpmyfaq
Introduced in: 0Fixed in: 3.2.0-alpha
Fixcomposer require thorsten/phpmyfaq:^3.2.0-alpha
Packagist/phpmyfaq/phpmyfaq
Introduced in: 0Fixed in: 3.2.0-alpha
Fixcomposer require phpmyfaq/phpmyfaq:^3.2.0-alpha

References