8.8
CVSSv3

CVE-2017-15730

Published: 22/10/2017 Updated: 14/03/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In phpMyFAQ prior to 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfaq phpmyfaq

Exploits

# Exploit Title: phpMyFAQ 298 CSRF Vulnerability # Date: 27-9-2017 # Exploit Author: Nikhil Mittal (Payatu Labs) # Vendor Homepage: wwwphpmyfaqde/ # Software Link: downloadphpmyfaqde/phpMyFAQ-298zip # Version: 298 # Tested on: MAC OS # CVE : 2017-15730 1 Description In phpMyFAQ before 298, there is Cross-Site Request ...