phpMyFAQ FAQ: Malicious File Upload Vulnerability Could Lead to Remote Code Execution
CVE-2024-28105
7.2HIGH
What is CVE-2024-28105?
The phpMyFAQ web application, a popular open-source solution for managing FAQs, is susceptible to a significant vulnerability involving the category image upload feature. This flaw arises from improper validation of the 'Content-type' and 'lang' parameters, which can be exploited by attackers to upload malicious files, particularly those with a .php extension. Such an exploit may result in unauthorized remote code execution on the affected system, posing severe security risks. Users are encouraged to upgrade to version 3.2.6 or later to mitigate this vulnerability and enhance system security.
Affected Version(s)
phpMyFAQ 3.2.5
