PT-2026-41354 · Thorsten · Phpmyfaq

Offset

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2026-45007

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail provider, and translation provider by querying /admin/api/configuration endpoints, violating least privilege access control.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-45007

Affected Products

Phpmyfaq