PT-2026-78395 · Phpmyfaq · Phpmyfaq
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.7
Description
A flaw exists in the two-factor authentication process where the failure counter is session-scoped and resets upon every successful password re-authentication. An attacker possessing a valid password can bypass the five-attempt limit by acquiring a new session cookie and re-authenticating to reset the counter, allowing for unbounded guessing of the Time-based One-Time Password (TOTP), which is a temporary code generated by an app to provide an extra layer of security.
Recommendations
Update to version 4.1.7 or later.
Exploit
Fix
DoS
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq