Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jvxm-3fc5-8pjr

Опубликовано: 19 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

EPSS

Процентиль: 17%
0.00255
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-304

Связанные уязвимости

CVSS3: 8.1
nvd
26 дней назад

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

CVSS3: 8.1
fstec
около 1 месяца назад

Уязвимость функций login() и getFromCookie() веб-приложения phpMyFAQ, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 17%
0.00255
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-304