PT-2026-51237 · Phpmyfaq · Phpmyfaq
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.4
Description
Missing authorization flaws in the
editUser() and updateUserRights() endpoints allow authenticated administrators to escalate privileges. An authenticated non-SuperAdmin user possessing the edit user permission can modify the is superadmin flag or grant arbitrary rights to an account, enabling them to gain full SuperAdmin access and complete control over the knowledge base.Recommendations
Upgrade to version 4.1.4.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq