Weak Password Recovery Mechanism for Forgotten Password in phpMyFAQ - #VU131755

 

Weak Password Recovery Mechanism for Forgotten Password in phpMyFAQ - #VU131755

Published: May 18, 2026


Vulnerability identifier: #VU131755
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-640
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to a weak password recovery mechanism in the password reset API endpoint when handling password reset requests with supplied username and email pairs. A remote attacker can send a specially crafted password reset request to disclose sensitive information.

The endpoint returns different responses for valid and invalid username and email pairs.


Affected software

phpMyFAQ

Remediation

Install security update from vendor's website.

phpMyFAQ - update to 4.1.3

External References

Related Security Bulletins