Authorization Bypass in phpMyFAQ by PhpMyFAQ Team
CVE-2014-6049

2.7LOW

Key Information:

Vendor

pHPMyFAQ

Status
Vendor
CVE Published:
28 August 2018

What is CVE-2014-6049?

This vulnerability in phpMyFAQ allows remote authenticated users with admin rights to exploit a crafted instance ID parameter to bypass normal authorization checks, thereby gaining potentially unauthorized access to administrative functions. It is crucial for users of phpMyFAQ to upgrade to version 2.8.13 or later to mitigate this security risk.

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.