Логотип exploitDog
bind:CVE-2024-55889
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-55889

Количество 2

Количество 2

nvd логотип

CVE-2024-55889

около 1 года назад

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-m3r7-8gw7-qwvc

около 1 года назад

thorsten/phpmyfaq Unintended File Download Triggered by Embedded Frames

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-55889

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.

CVSS3: 4.9
7%
Низкий
около 1 года назад
github логотип
GHSA-m3r7-8gw7-qwvc

thorsten/phpmyfaq Unintended File Download Triggered by Embedded Frames

CVSS3: 4.9
7%
Низкий
около 1 года назад

Уязвимостей на страницу