Missing Authorization in phpMyFAQ - #VU140901
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the attachments API endpoint when handling requests for attachments by FAQ record ID. A remote attacker can send a specially crafted request for a restricted FAQ record ID to disclose sensitive information.
Exposed data can include attachment filenames, generated attachment URLs, and the existence of attachments for restricted FAQ records. The advisory states that file contents were not disclosed in the demonstrated reproduction.