Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-76207

около 1 месяца назад

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-jvxm-3fc5-8pjr

около 1 месяца назад

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2026-12051

около 2 месяцев назад

Уязвимость функций login() и getFromCookie() веб-приложения phpMyFAQ, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-76207

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-jvxm-3fc5-8pjr

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

CVSS3: 8.1
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-12051

Уязвимость функций login() и getFromCookie() веб-приложения phpMyFAQ, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу