PT-2026-29423 · Phpmyfaq · Phpmyfaq
Wooseokdotkim
·
Published
2026-03-31
·
Updated
2026-04-02
·
CVE-2026-32629
CVSS v4.0
6.4
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.1
Description
prior to version 4.1.1, an unauthenticated attacker can submit a guest FAQ with an email address containing raw HTML that is accepted as valid by PHP's FILTER VALIDATE EMAIL function. This email is stored in the database without sanitization and rendered in the admin FAQ editor template using Twig's |raw filter, bypassing auto-escaping. This allows for the execution of arbitrary scripts in the administrator's browser when reviewing the FAQ, potentially leading to session cookie theft and full admin account takeover.
Recommendations
Update to version 4.1.1 or later.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq