PT-2026-78384 · Phpmyfaq · Phpmyfaq
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.7
Description
Insufficient protection of service data in the
userTracking() function of the UserSession class within the src/phpMyFAQ/User/UserSession.php file allows remote attackers to gain unauthorized access to protected information. When user tracking is enabled, password reset tokens are stored in a publicly accessible tracking file located at content/core/data/trackingDDMMYYYY. Unauthenticated attackers can read this file to extract reset tokens and replay them against the password reset API to take over user accounts.Recommendations
Update to version 4.1.7 or later.
As a temporary mitigation, disable the user tracking feature to prevent the storage of sensitive tokens in public files.
Exploit
Fix
Information Disclosure
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq