| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xvp4-phqj-cjr3 | phpMyFAQ: IDOR Account Takeover |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 30 May 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request. | |
| Title | phpMyFAQ - Insecure Direct Object Reference in User Password API | |
| First Time appeared |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| Weaknesses | CWE-266 | |
| CPEs | cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Phpmyfaq
Phpmyfaq phpmyfaq |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-30T01:55:57.200Z
Reserved: 2026-04-04T12:32:50.476Z
Link: CVE-2026-35671
Updated: 2026-05-30T01:55:51.066Z
Status : Deferred
Published: 2026-05-28T16:16:21.530
Modified: 2026-05-30T02:16:17.737
Link: CVE-2026-35671
No data.
OpenCVE Enrichment
Updated: 2026-05-28T18:00:11Z
Github GHSA