GHSA-m3r7-8gw7-qwvc

Suggest an improvement
Source
https://github.com/advisories/GHSA-m3r7-8gw7-qwvc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-m3r7-8gw7-qwvc/GHSA-m3r7-8gw7-qwvc.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-m3r7-8gw7-qwvc
Aliases
Published
2024-12-13T20:36:08Z
Modified
2026-08-24T00:35:36Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
thorsten/phpmyfaq Unintended File Download Triggered by Embedded Frames
Details

Summary

A vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an

and save FAQ record

  • once the edit page reloads, the malicious code will be downloaded onto the local machine without user interaction: image

  • (uploaded a POC for easy demonstration: https://roy.demo.phpmyfaq.de/admin/index.php?action=editentry&id=20&lang=en although a fresh installation overwrites this demo instance every 24 hours)

    (as a logged in normal user, visit: https://roy.demo.phpmyfaq.de/content/1/20/en/20.html)

    Impact

    Malicious code or binaries could be dropped on visitors' machines when visiting the FAQ platform. Take a worm or ransomware for instance.

    Database specific
    {
        "cwe_ids": [
            "CWE-451"
        ],
        "github_reviewed": true,
        "github_reviewed_at": "2024-12-13T20:36:08Z",
        "nvd_published_at": "2024-12-13T14:15:22Z",
        "severity": "MODERATE"
    }
    References

    Affected packages

    Packagist / thorsten/phpmyfaq

    Package

    Name
    thorsten/phpmyfaq
    Purl
    pkg:composer/thorsten/phpmyfaq

    Affected ranges

    Type
    ECOSYSTEM
    Events
    Introduced
    0 Unknown introduced version / All previous versions are affected
    Fixed
    3.2.10

    Affected versions

    2.*
    2.8.0-alpha2
    2.8.0-alpha3
    2.8.0-beta
    2.8.0-beta2
    2.8.0-beta3
    2.8.0-RC
    2.8.0-RC2
    2.8.0-RC3
    2.8.0-RC4
    2.8.0
    2.8.1
    2.8.2
    2.8.3
    2.8.4
    2.8.5
    2.8.6
    2.8.7
    2.8.8
    2.8.9
    2.8.10
    2.8.11
    2.8.12
    2.8.13
    2.8.14
    2.8.15
    2.8.16
    2.8.17
    2.8.18
    2.8.19
    2.8.20
    2.8.21
    2.8.22
    2.8.23
    2.8.24
    2.8.25
    2.8.26
    2.8.27
    2.8.28
    2.8.29
    2.9.0-alpha
    2.9.0-alpha2
    2.9.0-alpha3
    2.9.0-alpha4
    2.9.0-beta
    2.9.0-beta2
    2.9.0-rc
    2.9.0-rc2
    2.9.0-rc3
    2.9.0-rc4
    2.9.0
    2.9.1
    2.9.2
    2.9.3
    2.9.4
    2.9.5
    2.9.6
    2.9.7
    2.9.8
    2.9.9
    2.9.10
    2.9.11
    2.9.12
    2.9.13
    2.10.0-alpha
    3.*
    3.0.0-alpha
    3.0.0-alpha.2
    3.0.0-alpha.3
    3.0.0-alpha.4
    3.0.0-beta
    3.0.0-beta.2
    3.0.0-beta.3
    3.0.0-RC
    3.0.0-RC.2
    3.0.0
    3.0.1
    3.0.2
    3.0.3
    3.0.4
    3.0.5
    3.0.6
    3.0.7
    3.0.8
    3.0.9
    3.0.10
    3.0.11
    3.0.12
    3.1.0-alpha
    3.1.0-alpha.2
    3.1.0-alpha.3
    3.1.0-beta
    3.1.0-RC
    3.1.0
    3.1.1
    3.1.2
    3.1.3
    3.1.4
    3.1.5
    3.1.6
    3.1.7
    3.1.8
    3.1.9
    3.1.10
    3.1.11
    3.1.12
    3.1.13
    3.1.14
    3.1.15
    3.1.16
    3.1.17
    3.1.18
    3.2.0-alpha
    3.2.0-beta
    3.2.0-beta.2
    3.2.0-RC
    3.2.0-RC.2
    3.2.0-RC.4
    3.2.0
    3.2.1
    3.2.2
    3.2.3
    3.2.4
    3.2.5
    3.2.6
    3.2.7
    3.2.8
    3.2.9

    Database specific

    source
    "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-m3r7-8gw7-qwvc/GHSA-m3r7-8gw7-qwvc.json"