Email Registration Flaw in phpMyFAQ Application by Thorsten
CVE-2025-59943

8.1HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
3 October 2025

What is CVE-2025-59943?

The phpMyFAQ application is susceptible to an email registration issue that does not enforce unique email addresses during user account creation. This vulnerability enables an attacker to create multiple accounts using the same email address, leading to confusion in identifying user accounts. Since email serves as a primary means for password resets and notifications, this flaw can facilitate unauthorized access to user accounts, potentially escalating privileges or allowing account takeover in certain scenarios. The issue has been resolved in version 4.0.13.

Affected Version(s)

phpMyFAQ >= 4.0.7, < 4.0.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59943 : Email Registration Flaw in phpMyFAQ Application by Thorsten