CVE-2024-55889

CVSS V2 None CVSS V3 None
Description
phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.
Overview
  • CVE ID
  • CVE-2024-55889
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-13T13:44:57.630Z
  • Last Modified Date
  • 2024-12-13T20:42:24.897Z
History
Created Old Value New Value Data Type Notes
2024-12-14 13:50:27 Added to TrackCVE