Missing Authorization in phpMyFAQ - #VU140898

 

Missing Authorization in phpMyFAQ - #VU140898

Published: August 4, 2026


Vulnerability identifier: #VU140898
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the comments API endpoint when handling requests for comments by FAQ record ID. A remote attacker can send a specially crafted request for a restricted FAQ record ID to disclose sensitive information.

Exposed data can include comment text, commenter usernames, email addresses, timestamps, and the existence of comments for restricted FAQ records.


Affected software

phpMyFAQ

Remediation

Install security update from vendor's website.

phpMyFAQ - update to 4.1.7

External References