{"id":"CVE-2023-1882","aliases":["GHSA-jph3-3j24-pg3j"],"url":"https://o3.security/vulnerability/CVE-2023-1882","summary":"Cross-site Scripting (XSS) - DOM in thorsten/phpmyfaq","details":"thorsten/phpmyfaq prior to 3.1.12 is vulnerable to DOM cross-site scripting (XSS) because it fails to sanitize user input in the configuration privacy note URL parameter. This has been fixed in 3.1.12.","published":"2023-04-05T00:00:00Z","modified":"2026-08-12T03:51:47.760245475Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"},"epss":{"score":0.00532,"percentile":0.43708,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"thorsten/phpmyfaq","fixedVersion":"3.1.12"}],"fix":{"url":"https://github.com/thorsten/phpmyfaq/commit/49db615c300ae0f87795f20570f6f5bdccb1d2f2","label":"thorsten/phpmyfaq@49db615"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/8ab09a1c-cfd5-4ce0-aae3-d33c93318957"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1882.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1882"},{"type":"FIX","url":"https://github.com/thorsten/phpmyfaq/commit/49db615c300ae0f87795f20570f6f5bdccb1d2f2"},{"type":"PACKAGE","url":"https://github.com/thorsten/phpMyFAQ"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.760245475Z"}}