phpMyFAQ FAQ: Malicious File Upload Vulnerability Could Lead to Remote Code Execution
CVE-2024-28105

7.2HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
25 March 2024

What is CVE-2024-28105?

The phpMyFAQ web application, a popular open-source solution for managing FAQs, is susceptible to a significant vulnerability involving the category image upload feature. This flaw arises from improper validation of the 'Content-type' and 'lang' parameters, which can be exploited by attackers to upload malicious files, particularly those with a .php extension. Such an exploit may result in unauthorized remote code execution on the affected system, posing severe security risks. Users are encouraged to upgrade to version 3.2.6 or later to mitigate this vulnerability and enhance system security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

phpMyFAQ 3.2.5

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.