Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24421

Опубликовано: 24 янв. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

phpMyFAQ is an open source FAQ web application. Versions 4.0.16 and below have flawed authorization logic which exposes the /api/setup/backup endpoint to any authenticated user despite their permissions. SetupController.php uses userIsAuthenticated() but does not verify that the requester has configuration/admin permissions. Non-admin users can trigger a configuration backup and retrieve its path. The endpoint only checks authentication, not authorization, and returns a link to the generated ZIP. This issue is fixed in version 4.0.17.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
Версия до 4.0.17 (исключая)

EPSS

Процентиль: 2%
0.00014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
github
15 дней назад

phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)

EPSS

Процентиль: 2%
0.00014
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862