PT-2023-17315 · Thorsten · Phpmyfaq
Published
2023-04-05
·
Updated
2023-04-12
·
CVE-2023-1887
CVSS v3.1
8.3
Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H |
Exploit
Fix
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq
Published
2023-04-05
·
Updated
2023-04-12
·
CVE-2023-1887
8.3
High
Base vector | Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions:
thorsten/phpmyfaq versions prior to 3.1.12
Description:
The issue concerns business logic errors in the thorsten/phpmyfaq GitHub repository. Specifically, users with edit-only permissions could add and delete categories and add FAQs, despite their limited permissions. This has been fixed in version 3.1.12.
Recommendations:
For versions prior to 3.1.12, update to version 3.1.12 to resolve the issue. As a temporary workaround, consider restricting edit-only permissions to prevent unauthorized category and FAQ management until the update is applied.
Exploit
Fix