Incorrect authorization in phpMyFAQ - #VU130118
Published: May 5, 2026
phpMyFAQ
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in admin-api routes when handling requests to backend management API endpoints. A remote user can send a request to admin-only API endpoints to disclose sensitive information.
Depending on enabled features, exposed data may include version status, health-check information, LDAP configuration details, and Elasticsearch or OpenSearch status and statistics.