3.5
CVSSv2

CVE-2017-15727

Published: 22/10/2017 Updated: 14/03/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In phpMyFAQ prior to 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfaq phpmyfaq

Exploits

# Exploit Title: phpMyFAQ 298 Stored XSS Vulnerability # Date: 28-9-2017 # Exploit Author: Nikhil Mittal (Payatu Labs) # Vendor Homepage: wwwphpmyfaqde/ # Software Link: downloadphpmyfaqde/phpMyFAQ-298zip # Version: 298 # Tested on: MAC OS # CVE : 2017-15727 1 Description In phpMyFAQ before 299, there is Stored Cross ...