Inclusion of Sensitive Information in Log Files in phpMyFAQ - #VU140879
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over accounts.
The vulnerability exists due to insertion of sensitive information into log files in the user tracking feature and password reset handling when logging frontend requests containing password reset query strings to a publicly accessible tracking file. A remote attacker can read the exposed tracking file and replay leaked reset parameters to take over accounts.
User interaction is required because a target user must open a valid password reset link before the leaked reset parameters can be reused.