phpMyFAQ SQL Injection Vulnerability Allows Data Exfiltration and Account Takeover
CVE-2024-28107
8.8HIGH
What is CVE-2024-28107?
A SQL injection vulnerability has been identified in the phpMyFAQ web application, particularly affecting the insertentry and saveentry functions. This issue arises due to improper escaping of email addresses when modifying records. An authenticated user with privileges to add or edit FAQ entries could exploit this vulnerability to extract sensitive data, potentially take control of user accounts, and, in certain scenarios, achieve remote code execution (RCE). The issue has been resolved in the version 3.2.6.
Affected Version(s)
phpMyFAQ 3.2.5
