Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8g2-rwh5-6gg5

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

EPSS

Процентиль: 29%
0.00359
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-799

Связанные уязвимости

nvd
14 дней назад

phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission requests. Unauthenticated attackers can bypass CAPTCHA protection and submit unlimited questions directly, causing database pollution and triggering outgoing mail notifications.

CVSS3: 5.3
fstec
29 дней назад

Уязвимость веб-приложения phpMyFAQ, связанная с недостаточным контролем за частотой взаимодействий, позволяющая нарушителю обойти существующие механизмы безопасности

EPSS

Процентиль: 29%
0.00359
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-799