Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35671

Опубликовано: 28 мая 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request.

EPSS

Процентиль: 23%
0.00303
Низкий

8.8 High

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 8.8
github
3 месяца назад

phpMyFAQ: IDOR Account Takeover

EPSS

Процентиль: 23%
0.00303
Низкий

8.8 High

CVSS3

Дефекты

CWE-266