top of page
perceptive_background_267k.jpg

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrator…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

phpMyFAQ versions before 4.1.3 contain an insecure direct object reference vulnerability in the admin API user password endpoint. The vulnerability allows authenticated administrators to change any user's password without proper authorization verification. Attackers with low-privilege admin credentials can exploit this by modifying the userId parameter in the overwrite-password API request. This enables privilege escalation from a regular admin account to SuperAdmin level access. The vulnerability affects the admin API specifically and requires authenticated access to exploit.

Technical details

Mitigation steps:

Affected products:

phpMyFAQ

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page