Missing Authorization in phpMyFAQ - #VU140898
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the comments API endpoint when handling requests for comments by FAQ record ID. A remote attacker can send a specially crafted request for a restricted FAQ record ID to disclose sensitive information.
Exposed data can include comment text, commenter usernames, email addresses, timestamps, and the existence of comments for restricted FAQ records.