PT-2026-78393 · Phpmyfaq · Phpmyfaq
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.7
Description
Insufficient enforcement of the
CONFIGURATION EDIT permission on administrative API read endpoints allows any authenticated user to access sensitive administrative data. By utilizing a valid session, an attacker can retrieve information regarding LDAP server topology, bind account names, search bases, index statistics, and site analytics. The affected endpoints relate to the configuration of LDAP, Elasticsearch, OpenSearch, and the dashboard.Recommendations
Update to version 4.1.7 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq