vendor:
phpMyFAQ
by:
Nikhil Mittal (Payatu Labs)
7,5
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: phpMyFAQ
Affected Version From: 2.9.8
Affected Version To: 2.9.8
Patch Exists: YES
Related CWE: 2017-15730
CPE: 2.9.8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MAC OS
2017
phpMyFAQ 2.9.8 CSRF Vulnerability
In phpMyFAQ before 2.9.8, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
Mitigation:
Update to phpMyFAQ Version 2.9.9