top of page
perceptive_background_267k.jpg

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrator…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 17:06:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

phpMyFAQ versions before 4.1.3 contain an insecure direct object reference vulnerability in the admin API user password endpoint. The vulnerability allows authenticated administrators to change any user's password without proper authorization verification. Attackers with low-privilege admin credentials can exploit this by modifying the userId parameter in the overwrite-password API request to escalate privileges to SuperAdmin level. This represents a significant privilege escalation vulnerability that compromises the application's access control mechanisms.

Technical details

Mitigation steps:

Affected products:

phpMyFAQ

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page