phpMyFAQ 是一款开源的 FAQ 网络应用程序。在 4.1.6 版本之前的构建中, 方法使用 构建 SQL 语句,并将用户提供的停止词(stop word)值直接拼接到查询字符串中,而没有调用应用程序的数据库转义函数对其进行转义。其相邻方法 (用于修改现有停止词)则正确地对其同类输入进行了转义。该遗漏仅局限于 (插入)代码路径。能够访问停止词管理功能且经过身份认证的管理员,可以提交精心构造的值作为 “word” 参数,从而突破 SQL 字符串字面量,注入任意 SQL 语句,例如删除表、外泄数据或修改数据库中的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56736 | 8.2 HIGH | phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submiss |
| CVE-2026-56737 | 8.1 HIGH | phpMyFAQ's two-factor authentication login bypasses the password factor |
| CVE-2026-47132 | 5.4 MEDIUM | phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumer |
No comments yet