Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2mwq-hcmq-fqq4

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 5.3

Описание

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

EPSS

Процентиль: 27%
0.00334
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-377

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 месяца назад

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

CVSS3: 5.3
fstec
около 2 месяцев назад

Уязвимость веб-интерфейса веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 27%
0.00334
Низкий

6 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-377