PT-2024-19276 · Phpmyfaq · Phpmyfaq
Pinkdraconian
·
Published
2024-02-05
·
Updated
2024-02-12
·
CVE-2024-22208
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 3.2.5
Description
The 'sharing FAQ' functionality in phpMyFAQ allows any unauthenticated actor to misuse the application to send arbitrary emails to a large range of targets. The front-end of this functionality allows any phpMyFAQ articles to be shared with 5 email addresses, but the backend does not limit the number of email addresses that can be sent with a single request. An attacker can solve a single CAPTCHA and send thousands of emails at once, utilizing the target application's email server to send phishing messages. This can lead to the server being blacklisted, causing all emails to end up in spam, and can also result in reputational damages.
Recommendations
For versions prior to 3.2.5, update to version 3.2.5 to resolve the issue. As a temporary workaround, consider restricting access to the 'sharing FAQ' functionality to prevent unauthenticated actors from sending arbitrary emails. Additionally, monitor email server logs for suspicious activity and consider implementing additional security measures to prevent phishing attacks.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpmyfaq