Files or Directories Accessible to External Parties in phpMyFAQ - #VU140882
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to files accessible to external parties in the content backup API when creating and downloading a content backup. A remote attacker can race requests to retrieve a leftover or temporarily exposed content.zip file to disclose sensitive information.
User interaction is required to trigger backup creation in the affected workflow.