phpMyFAQ FAQ: Malicious File Upload Vulnerability Could Lead to Remote Code Execution
CVE-2024-28105
What is CVE-2024-28105?
The phpMyFAQ web application, a popular open-source solution for managing FAQs, is susceptible to a significant vulnerability involving the category image upload feature. This flaw arises from improper validation of the 'Content-type' and 'lang' parameters, which can be exploited by attackers to upload malicious files, particularly those with a .php extension. Such an exploit may result in unauthorized remote code execution on the affected system, posing severe security risks. Users are encouraged to upgrade to version 3.2.6 or later to mitigate this vulnerability and enhance system security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
phpMyFAQ 3.2.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
