Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjx5-c2mr-w8c7

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.

EPSS

Процентиль: 38%
0.00461
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 5.3
nvd
25 дней назад

phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.

CVSS3: 5.3
fstec
около 1 месяца назад

Уязвимость файла src/phpMyFAQ/Controller/Api/SetupController.php веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00461
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-306