Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hccc-74hg-j43v

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.

EPSS

Процентиль: 16%
0.00252
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.8
nvd
22 дня назад

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.

CVSS3: 8.8
fstec
около 1 месяца назад

Уязвимость метода userTracking() класса UserSession файла src/phpMyFAQ/User/UserSession.php веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 16%
0.00252
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-200