Security Advisory

CVE-2024-55889

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-12-13 13:44:57
Last updated 2024-12-13 20:42:24
Assigner GitHub_M
CVSS score 4.9
State PUBLISHED

Description

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.