CVE-2023-1883
MEDIUM5.4EPSS 0.40%thorsten/phpmyfaq vulnerable to improper access control
Published: 4/5/2023Modified: 11/8/2023
Description
thorsten/phpmyfaq prior to 3.1.12 is vulnerable to improper access control when FAQ News is marked as inactive in settings and have comments enabled, allowing comments to be posted on inactive FAQs. This has been fixed in 3.1.12.
Affected packages (1)
- Packagist/thorsten/phpmyfaqfrom 0, < 3.1.12
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |