Aller au contenu

Fiche vulnérabilité

CVE-2025-59943 : faille critique phpmyfaq phpmyfaq (CVSS 9.8)

Description

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
3 oct. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • phpmyfaq phpmyfaq

Références

Rechercher une autre vulnérabilité dans la base CVE