Missing Authorization in phpMyFAQ - #VU140900
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in frontend FAQ comment rendering when rendering a restricted FAQ page. A remote attacker can request a restricted FAQ page to disclose sensitive information.
The page can display an access-denied FAQ body while still rendering the associated comment content and commenter information.