PT-2023-19516 · Thorsten · Phpmyfaq

CVE-2023-2429

·

Publicado

2023-04-30

·

Atualizado

2025-01-30

CVSS v3.1

6.6

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions thorsten/phpmyfaq versions prior to 3.1.13
Description The issue is related to improper access control in the thorsten/phpmyfaq GitHub repository. Specifically, phpMyFAQ does not properly validate email addresses when updating user profiles, allowing an attacker to manipulate their email address and change it to another email address that is already registered in the system. This includes email addresses belonging to other users, such as the administrator. Once the attacker has control of the other user's email address, they can request to remove the user from the system, leading to a loss of data and access.
Recommendations For versions prior to 3.1.13, update to version 3.1.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the user profile update functionality to minimize the risk of exploitation. Additionally, restrict the ability to remove users from the system to prevent data loss and access issues.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2429
GHSA-R69V-Q48G-3966

Produtos afetados

Phpmyfaq