Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function
Vulnerability Description
phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML containing crafted image paths that are processed during PDF generation. The path resolution logic locates the substring "content" within a user-controlled path using strpos(); when "content" is absent, strpos() returns false, which becomes 0 when cast to an integer, preserving the entire attacker-controlled path. This path is later passed to file_get_contents() without canonicalization or root-directory containment validation, which may allow reading of files outside the intended content directory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
phpMyFAQ 路径遍历漏洞
Vulnerability Description
phpmyfaq是phpmyfaq团队开源的一套FAQ知识库管理系统。 phpMyFAQ 4.1.5之前版本存在路径遍历漏洞,该漏洞源于concatenatePaths()函数中存在路径遍历问题,可能导致具有FAQ编辑权限的用户读取预期内容目录之外的文件。
CVSS Information
N/A
Vulnerability Type
N/A