Description
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field in phpMyFAQ's user control panel page is vulnerable to stored XSS attacks due to the inadequacy of PHP's `FILTER_VALIDATE_EMAIL` function, which only validates the email format, not its content. This vulnerability enables an attacker to execute arbitrary client-side JavaScript within the context of another user's phpMyFAQ session. This vulnerability is fixed in 3.2.6.
Remediation
References
Related Vulnerabilities
Squid CVE-2018-1000024 Vulnerability (CVE-2018-1000024)
MySQL CVE-2015-2568 Vulnerability (CVE-2015-2568)
WordPress Plugin Slideshow Gallery 2 'border' Parameter Cross-Site Scripting (1.1.4)
Drupal Core 9.1.x Multiple Security Bypass Vulnerabilities (9.1.0 - 9.1.12)
WordPress Plugin Duo Two-Factor Authentication Security Bypass (1.8.1)