Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-75920

Опубликовано: 19 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:*
Версия до 4.1.6 (исключая)

EPSS

Процентиль: 27%
0.00334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-377

Связанные уязвимости

CVSS3: 5.3
github
около 1 месяца назад

phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.

CVSS3: 5.3
fstec
около 2 месяцев назад

Уязвимость веб-интерфейса веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 27%
0.00334
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-377