PT-2026-41355 · Phpmyfaq · Phpmyfaq

·

CVE-2026-45008

·

Published

2026-05-06

·

Updated

2026-05-15

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions phpMyFAQ versions prior to 4.1.2
Description A path traversal issue exists in the deleteClientFolder() function. This allows administrators with the INSTANCE DELETE permission to delete arbitrary directories. An attacker can achieve this by submitting traversal sequences in the client URL parameter to recursively delete directories outside the intended client folder scope.
Recommendations Update to version 4.1.2 or later. As a temporary workaround, restrict the INSTANCE DELETE permission to only highly trusted administrators.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45008
GHSA-GH9P-Q46P-57G2
GHSA-RMQR-H98C-QG2M

Affected Products

Phpmyfaq