CVE 4.3 MEDIUM

phpMyFAQ – Missing Permission Check on 12 Configuration API Endpoints Allows Information Disclosure_CVE-2026-45007

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail provider, and translation provider by querying /admin/api/configuration endpoints, violating least privilege access control.

Basic Information

ID CVE-2026-45007
Source VulnCheck
Published May 15, 2026 at 18:36

Affected Product

Vendor thorsten
Product phpmyfaq
Affected Versions thorsten phpmyfaq 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.