phpMyFAQ是Thorsten Rinne个人开发者的一个多语言、完全由数据库驱动的常见问题解答系统。 phpMyFAQ 4.0.16及之前版本存在安全漏洞,该漏洞源于授权逻辑缺陷,可能导致非管理员用户触发配置备份并获取其路径。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24420 | 6.5 MEDIUM | phpMyFAQ: Attachment download allowed without dlattachment right (broken access control) |
| CVE-2026-24422 | 5.3 MEDIUM | phpMyFAQ: Public API endpoints expose emails and invisible questions |
No comments yet