A vulnerability was found in the PHP-FTS library up to version 1.1.3, affecting the SearchEngine::matchesSingleFilter function in the src/SearchEngine.php file. This issue allows for incorrect comparison due to loose filtering logic. The vulnerability can be exploited remotely, and a patch has been released in version 1.1.4. Users are advised to upgrade to the patched version to mitigate this issue.
A cross-site scripting vulnerability exists in the SearchEngine::buildHighlights function of the olivier-ls PHP-FTS library up to version 1.1.2. This issue allows remote attackers to inject malicious scripts by manipulating the Query argument. The vulnerability has been publicly disclosed and an exploit has been made available. However, the attack complexity is low and requires user interaction.