Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-76213

около 1 месяца назад

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a fresh session cookie and repeatedly re-authenticating to reset the counter, enabling unbounded TOTP code guessing.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-xgjh-9vcx-v63q

около 1 месяца назад

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a fresh session cookie and repeatedly re-authenticating to reset the counter, enabling unbounded TOTP code guessing.

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2026-12053

около 2 месяцев назад

Уязвимость файла src/phpMyFAQ/Controller/Frontend/AuthenticationController.php веб-приложения phpMyFAQ, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-76213

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a fresh session cookie and repeatedly re-authenticating to reset the counter, enabling unbounded TOTP code guessing.

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
github логотип
GHSA-xgjh-9vcx-v63q

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. Attackers with a valid password can bypass the five-attempt limit by obtaining a fresh session cookie and repeatedly re-authenticating to reset the counter, enabling unbounded TOTP code guessing.

CVSS3: 7.4
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-12053

Уязвимость файла src/phpMyFAQ/Controller/Frontend/AuthenticationController.php веб-приложения phpMyFAQ, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу