PT-2026-41355 · Phpmyfaq · Phpmyfaq
CVSS v4.0
7.0
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.2
Description
A path traversal issue exists in the
deleteClientFolder() function. This allows administrators with the INSTANCE DELETE permission to delete arbitrary directories. An attacker can achieve this by submitting traversal sequences in the client URL parameter to recursively delete directories outside the intended client folder scope.Recommendations
Update to version 4.1.2 or later.
As a temporary workaround, restrict the
INSTANCE DELETE permission to only highly trusted administrators.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq