In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/thorsten/phpMyFAQ/commit/cb648f0d5690b81647dd5c9efe942ebf6cce7da9 | issue tracking third party advisory patch |