PT-2026-44382 · Phpmyfaq · Phpmyfaq
Cyberhunter127
·
Published
2026-05-20
·
Updated
2026-05-30
·
CVE-2026-35671
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpMyFAQ versions prior to 4.1.3
Description
An Insecure Direct Object Reference (IDOR) exists in the Admin API, which allows authenticated administrators to change the password of any user account, including SuperAdmin accounts, without proper authorization verification. An attacker with low-privilege admin credentials can escalate privileges to full SuperAdmin control by modifying the
userId parameter in the request body. The issue occurs within the overwritePassword() function located in the /admin/api/user/overwrite-password endpoint, as the system fails to verify if the requesting administrator has the permission to modify the target user or if the target user has equal or lower privilege levels.Recommendations
Update to version 4.1.3 or later.
As a temporary workaround, restrict access to the
/admin/api/user/overwrite-password endpoint to only the highest privilege levels.Exploit
Fix
IDOR
Improper Privilege Management
Missing Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpmyfaq