Description
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with admin privileges can upload an attachment containing JS code without extension and the application will render it as HTML which allows for XSS attacks.
Remediation
References
Related Vulnerabilities
Joomla URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-5608)
WordPress Plugin File Manager Unspecified Vulnerability (2.2.0)
WordPress Plugin Participants Database Cross-Site Scripting (1.7.5.9)
Jetty Uncontrolled Resource Consumption Vulnerability (CVE-2022-2048)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-5682)