PT-2022-24019 · Phpmyfaq · Phpmyfaq

Published

2022-10-29

·

Updated

2022-10-31

·

CVE-2022-3754

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 3.1.8
Description The issue concerns weak password requirements in the phpMyFAQ repository. Specifically, versions prior to 3.1.8 are affected due to inadequate password length requirements. Version 3.1.8 introduces a minimum password length of eight characters, addressing this issue.
Recommendations For versions prior to 3.1.8, update to version 3.1.8 or later to introduce the eight-character minimum password length requirement and mitigate the risk associated with weak passwords.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-3754
GHSA-2RR3-RV49-P42F

Affected Products

Phpmyfaq