PT-2026-78390 · Phpmyfaq · Phpmyfaq
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions 3.1.0 through 4.1.6
Description
An authentication bypass exists in the
AuthLdap::create() function. When LDAP authentication is enabled, a successful LDAP bind triggers the User::setStatus('active') function unconditionally. This action overwrites the account status column of an existing local account, changing it from 'blocked' to 'active'. Consequently, users with administratively blocked local accounts can restore access and log in via LDAP. This state transition is not recorded in logs, preventing administrators from detecting the override.Recommendations
Update phpMyFAQ to version 4.1.7.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq