PT-2026-78388 · Phpmyfaq · Phpmyfaq
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.7
Description
An issue exists where the software fails to validate the active status of an FAQ entry in the PDF export endpoint. This allows unauthenticated attackers to retrieve metadata from draft or unpublished FAQs by accessing the public PDF export route using sequential FAQ identifiers. The exposed information includes titles, solution IDs, author names, and last-update timestamps.
Recommendations
Update to version 4.1.7 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq