highCVSS 7.6Vulnerability

GHSA-9525-27vj-c8r8

### Summary A stored XSS vulnerability in the comment rendering pipeline allows an authenticated user to inject JavaScript that executes for every visitor of an affected FAQ or News page. An attacker with a registered account can steal admin session cookies and take over the application. ### Details `Utils::parseUrl()` (`phpmyfaq/src/phpMyFAQ/Utils.php`, line 281) converts URLs in comment text into clickable `<a>` tags at render time: $pattern = '/(https?:\/\/[^\s]+)/i'; $replacement = '<a href="$1">$1</a>'; return preg_replace($pattern, $replacement, $string); The regex `[^\s]+` matches `"` and `<`, and the URL is inserted into the href attribute with no htmlspecialchars() call. A URL with a literal `"` closes the attribute early and allows injecting event handlers like onmouseover. This only reaches the sink when `main.enableCommentEditor` is enabled. In that path, comment text goes through `sanitizeHtmlComment()` instead of `FILTER_SANITIZE_SPECIAL_CHARS` — which encodes `"` — so the double-quote survives to storage. The comment is then passed through parseUrl() and rendered via `{{ comment.comment|raw }}` in `comment.macros.twig` (line 40), which disables Twig auto-escaping. The same sink exists in the admin comment panel (`admin/content/comments.twig`, lines 62 and 112), so admins viewing the panel are also affected. No Content-Security-Policy headers are set anywhere in the app. ### PoC Requirements: - main.enableCommentEditor = true (set in admin Configuration panel) - attacker has any registered user account - one FAQ entry with comments allowed exists Steps: 1. Log in as a registered user and open a FAQ with comments. 2. Submit the following as the comment text: https://www.evil.com/"onmouseover="alert(document.cookie) (www. prefix required — parseUrl strips https:// then only re-adds it for www. URLs, which is what triggers the linkification) 3. Any user who views that FAQ page and hovers the link triggers the payl

Properties

ghsa_id
GHSA-9525-27vj-c8r8
summary
phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering
severity
high
cvss_score
7.6
cve_id
GHSA-9525-27vj-c8r8
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-05-06T20:10:48Z
source_url
https://github.com/advisories/GHSA-9525-27vj-c8r8
ghsa_updated
2026-05-06T20:10:49Z

Related Entities (7)

AFFECTS (2)

[Software]composer/phpMyFAQ/phpMyFAQ
[Software]composer/thorsten/phpMyFAQ

VULNERABLE_TO (2)

[Software]composer/phpMyFAQ/phpMyFAQ
[Software]composer/thorsten/phpMyFAQ

HAS_WEAKNESS (2)

[Weakness]Improper Encoding or Escaping of Output
[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-9525-27vj-c8r8 (CVSS 7.6) — Ninja Signal Threat Intelligence | Ninja Signal