logo

CVE-2023-1883 thorsten/phpmyfaq

Package

Manager: composer
Name: thorsten/phpmyfaq
Vulnerable Version: >=0 <3.1.12

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00265 pctl0.49722

Details

thorsten/phpmyfaq vulnerable to improper access control thorsten/phpmyfaq prior to 3.1.12 is vulnerable to improper access control when FAQ News is marked as inactive in settings and have comments enabled, allowing comments to be posted on inactive FAQs. This has been fixed in 3.1.12.

Metadata

Created: 2023-04-05T18:30:18Z
Modified: 2023-04-06T15:07:52Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-2wjp-w7g7-h63q/GHSA-2wjp-w7g7-h63q.json
CWE IDs: ["CWE-284"]
Alternative ID: GHSA-2wjp-w7g7-h63q
Finding: F039
Auto approve: 1