Description
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02)
WordPress Plugin Craw Data Server-Side Request Forgery (1.0.0)
WordPress Plugin Vospari Forms Cross-Site Scripting (1.3)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9517)