CVE-2019-7402: Phpmywind
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in PHPMyWind 5.5. The GetQQ function in include/func.class.php allows XSS via the cfg_qqcode parameter. This can be exploited via CSRF.
Affected products
- Phpmywind Phpmywind: version 5.5 only
Published 2019-02-05. Last modified 2026-06-17.