Description
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
Remediation
References
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Cross-Site Request Forgery (2.6.01)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
WordPress Plugin Advanced Custom Fields:reCAPTCHA Field Security Bypass (1.1.1)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2014-0082)