GHSA-9525-27vj-c8r8
### Summary A stored XSS vulnerability in the comment rendering pipeline allows an authenticated user to inject JavaScript that executes for every visitor of an affected FAQ or News page. An attacker with a registered account can steal admin session cookies and take over the application. ### Details `Utils::parseUrl()` (`phpmyfaq/src/phpMyFAQ/Utils.php`, line 281) converts URLs in comment text into clickable `<a>` tags at render time: $pattern = '/(https?:\/\/[^\s]+)/i'; $replacement = '<a href="$1">$1</a>'; return preg_replace($pattern, $replacement, $string); The regex `[^\s]+` matches `"` and `<`, and the URL is inserted into the href attribute with no htmlspecialchars() call. A URL with a literal `"` closes the attribute early and allows injecting event handlers like onmouseover. This only reaches the sink when `main.enableCommentEditor` is enabled. In that path, comment text goes through `sanitizeHtmlComment()` instead of `FILTER_SANITIZE_SPECIAL_CHARS` — which encodes `"` — so the double-quote survives to storage. The comment is then passed through parseUrl() and rendered via `{{ comment.comment|raw }}` in `comment.macros.twig` (line 40), which disables Twig auto-escaping. The same sink exists in the admin comment panel (`admin/content/comments.twig`, lines 62 and 112), so admins viewing the panel are also affected. No Content-Security-Policy headers are set anywhere in the app. ### PoC Requirements: - main.enableCommentEditor = true (set in admin Configuration panel) - attacker has any registered user account - one FAQ entry with comments allowed exists Steps: 1. Log in as a registered user and open a FAQ with comments. 2. Submit the following as the comment text: https://www.evil.com/"onmouseover="alert(document.cookie) (www. prefix required — parseUrl strips https:// then only re-adds it for www. URLs, which is what triggers the linkification) 3. Any user who views that FAQ page and hovers the link triggers the payl
Properties
- ghsa_id
- GHSA-9525-27vj-c8r8
- summary
- phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering
- severity
- high
- cvss_score
- 7.6
- cve_id
- GHSA-9525-27vj-c8r8
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-05-06T20:10:48Z
- source_url
- https://github.com/advisories/GHSA-9525-27vj-c8r8
- ghsa_updated
- 2026-05-06T20:10:49Z
Related Entities (7)
AFFECTS (2)
VULNERABLE_TO (2)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph