CVE-2024-28107 is a high-severity SQL injection vulnerability affecting phpMyFAQ versions prior to 3.2.6. This flaw, found in the insertentry and saveentry functions, allows authenticated users with FAQ news editing privileges to inject malicious SQL queries through improper email address escaping. Successful exploitation can lead to data exfiltration, account compromise, and potentially remote code execution. While no active exploitation or public exploit code is currently reported, its high CVSS score of 8.8 and FAUCET Risk Score of 70/100 indicate a significant risk. Organizations using affected phpMyFAQ versions should prioritize patching to mitigate this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.5CPE matchmatch criteria | cpe:2.3:a:phpmyfaq:phpmyfaq:3.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.