The admin backend in phpMyFAQ before 2.9.11 allows CSV injection in reports.
| Software | From | Fixed in |
|---|---|---|
phpmyfaq / phpmyfaq
|
- | 2.9.11 |