Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions
Vulnerability Description
phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated administrator can exploit this by assigning high-value permissions to a group they belong to, inheriting those rights and escalating privileges up to full administrative control.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
thorsten phpMyFAQ 权限许可和访问控制问题漏洞
Vulnerability Description
thorsten phpMyFAQ是thorsten的文档管理系统。 thorsten phpMyFAQ 4.1.5之前版本存在权限许可和访问控制问题漏洞,该漏洞源于GroupController::updatePermissions函数在权限提升过程中未验证GROUP_EDIT管理员自身是否持有相应权限,允许委派管理员通过将高价值权限分配给所属组,继承这些权限并提升至完全管理控制权。
CVSS Information
N/A
Vulnerability Type
N/A