Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-66397

Опубликовано: 27 июл. 2026
Источник: nvd
EPSS Низкий

Описание

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

EPSS

Процентиль: 25%
0.00325
Низкий

Дефекты

CWE-22

Связанные уязвимости

github
10 дней назад

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.

EPSS

Процентиль: 25%
0.00325
Низкий

Дефекты

CWE-22