peter bassill · operator
$ cve CVE-2024-55889 JSON

CVE-2024-55889 EXPLOIT

4.9
MEDIUM · CVSS 3.1 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

phpMyFAQ is an open source FAQ web application. Prior to version 3.2.10, a vulnerability exists in the FAQ Record component where a privileged attacker can trigger a file download on a victim's machine upon page visit by embedding it in an <iframe> element without user interaction or explicit consent. Version 3.2.10 fixes the issue.

Scoring

CVSS4.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS2.19% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-451
On CISA KEVno
Public exploityes
Published2024-12-13
Last modified2026-06-17

Affected (1)

VendorProduct
phpmyfaqphpmyfaq

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD