PT-2025-47176 · Phpmyfaq · Phpmyfaq

Published

2025-11-17

·

Updated

2026-01-05

·

CVE-2025-62519

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.0.14
Description phpMyFAQ is an open source FAQ web application. A privileged user with 'Configuration Edit' permissions can execute arbitrary SQL commands due to an authenticated SQL injection flaw in the main configuration update functionality. Successful exploitation could lead to a full compromise of the database, including the ability to read, modify, or delete all data, and potentially enable remote code execution depending on the database configuration.
Recommendations Update phpMyFAQ to version 4.0.14 or later.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-62519
GHSA-FXM2-CMWJ-QVX4

Affected Products

Phpmyfaq