Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp5x-wfgj-283r

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.

EPSS

Процентиль: 27%
0.00335
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-863

Связанные уязвимости

nvd
14 дней назад

phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.

CVSS3: 4.3
fstec
29 дней назад

Уязвимость веб-приложения phpMyFAQ, связанная с недостатками процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 27%
0.00335
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-863