PT-2026-78391 · Phpmyfaq · Phpmyfaq
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.6
Description
Failure to validate the
security.enableRegistration setting in API endpoints allows the creation of user accounts even when registration is disabled. This bypasses the restriction enforced on the HTML registration page by submitting requests to the 'POST /api/register' or 'POST /api/v3.1/register' endpoints.Recommendations
Update to version 4.1.6 or later.
Restrict access to the 'POST /api/register' and 'POST /api/v3.1/register' endpoints as a temporary mitigation.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq