A vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an
and save FAQ recordonce the edit page reloads, the malicious code will be downloaded onto the local machine without user interaction:
(uploaded a POC for easy demonstration: https://roy.demo.phpmyfaq.de/admin/index.php?action=editentry&id=20&lang=en although a fresh installation overwrites this demo instance every 24 hours)
(as a logged in normal user, visit: https://roy.demo.phpmyfaq.de/content/1/20/en/20.html)
Malicious code or binaries could be dropped on visitors' machines when visiting the FAQ platform. Take a worm or ransomware for instance.
{
"cwe_ids": [
"CWE-451"
],
"github_reviewed": true,
"github_reviewed_at": "2024-12-13T20:36:08Z",
"nvd_published_at": "2024-12-13T14:15:22Z",
"severity": "MODERATE"
}