Количество 3
Количество 3
CVE-2026-75919
phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.
GHSA-gjx5-c2mr-w8c7
phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives.
BDU:2026-12007
Уязвимость файла src/phpMyFAQ/Controller/Api/SetupController.php веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-75919 phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-gjx5-c2mr-w8c7 phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrations and create configuration backups when maintenance mode is enabled. Attackers can call POST /api/setup/update-database and POST /api/setup/backup endpoints to execute database updates, disable maintenance mode, and extract database credentials from generated ZIP archives. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
BDU:2026-12007 Уязвимость файла src/phpMyFAQ/Controller/Api/SetupController.php веб-приложения phpMyFAQ, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу