CVE 7.5 HIGH

phpMyFAQ – SQL Injection in CurrentUser::setTokenData via Unescaped OAuth Token Fields_CVE-2026-46359

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated attackers to execute arbitrary SQL by injecting malicious OAuth token claims. Attackers with Azure AD accounts containing SQL metacharacters in display names or JWT claims can break out of string literals and execute arbitrary database queries.

Basic Information

ID CVE-2026-46359
Source VulnCheck
Published May 15, 2026 at 18:36

Affected Product

Vendor thorsten
Product phpmyfaq
Affected Versions thorsten phpmyfaq 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.