phpMyFAQ 2.9.8 - Cross-Site Scripting (2)

ID: 101785
CVE: None
Download vulnerable application: None
# Exploit Title: phpMyFAQ 2.9.8 Stored XSS
# Vendor Homepage:
# Software Link:
# Exploit Author: Ishaq Mohammed
# Contact:
# Website:
# Category: webapps
# CVE: CVE-2017-14619

1. Description

Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows
remote attackers to inject arbitrary web script or HTML via the "Title of
your FAQ" field in the Configuration Module.

2. Proof of Concept

Steps to Reproduce:

   1. Open the affected link http://localhost/phpmyfaq/admin/?action=config
   with logged in user with administrator privileges
   2. Enter the <marquee onscroll=alert(document.cookie)> in the “Title of
   your FAQ field”
   3. Save the Configuration
   4. Login using any other user or simply click on the phpMyFAQ on the
   top-right hand side of the web portal

3. Solution:

The Vulnerability will be fixed in the next release of phpMyFAQ
1-4-2 (www01)