Количество 2
Количество 2
CVE-2026-35671
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request.
GHSA-xvp4-phqj-cjr3
phpMyFAQ: IDOR Account Takeover
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35671 phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request. | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
GHSA-xvp4-phqj-cjr3 phpMyFAQ: IDOR Account Takeover | CVSS3: 8.8 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу