phpMyFAQ 是一个开源的常见问题解答(FAQ)Web 应用。在 4.2.0-alpha 版本之前,phpMyFAQ 的聊天用户搜索功能中存在一个经过认证的 SQL LIKE 通配符注入漏洞,该漏洞允许任何已登录的用户绕过预设的显示名称搜索过滤器,从而枚举活跃用户。该端点虽然会对 SQL 字符串语法进行转义,但并未对 和 进行转义,导致这两个字符作为有效的 通配符仍然起作用。版本 4.2.0-alpha 已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56738 | 8.5 HIGH | phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion |
| CVE-2026-56736 | 8.2 HIGH | phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submiss |
| CVE-2026-56737 | 8.1 HIGH | phpMyFAQ's two-factor authentication login bypasses the password factor |
No comments yet