In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://github.com/thorsten/phpMyFAQ/commit/a249b4645fb86f6a9fbe5d2344ab1cbdb906b75c | patch third party advisory issue tracking |
https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2017-15808.md |