{"id":"CVE-2023-6890","aliases":["GHSA-4h37-q5j3-hw96"],"url":"https://o3.security/vulnerability/CVE-2023-6890","summary":"Cross-site Scripting (XSS) - Stored in thorsten/phpmyfaq","details":"Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.17.","published":"2023-12-16T08:57:31.033Z","modified":"2026-08-12T03:51:35.663427976Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"thorsten/phpmyfaq","fixedVersion":"3.1.17"}],"fix":{"url":"https://github.com/thorsten/phpmyfaq/commit/97d90ebbe11ebc6081bf49a2ba4b60f227cd1b43","label":"thorsten/phpmyfaq@97d90eb"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/2cf11678-8793-4fa1-b21a-f135564a105d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6890.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6890"},{"type":"FIX","url":"https://github.com/thorsten/phpmyfaq/commit/97d90ebbe11ebc6081bf49a2ba4b60f227cd1b43"},{"type":"PACKAGE","url":"https://github.com/thorsten/phpmyfaq"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.663427976Z"}}