Improper access control in phpMyFAQ - CVE-2024-22208
Published: February 5, 2024 / Updated: May 5, 2026
phpMyFAQ
Thorsten Rinne
Description
The vulnerability allows a remote attacker to send arbitrary emails for phishing purposes.
The vulnerability exists due to improper access control in the sharing FAQ functionality when handling share requests. A remote attacker can submit a specially crafted request to send arbitrary emails for phishing purposes.
A single solved CAPTCHA can be abused to send thousands of emails because the backend does not enforce the front-end recipient limit, and the email content and shared link can be modified.