Email Registration Flaw in phpMyFAQ Application by Thorsten
CVE-2025-59943
8.1HIGH
What is CVE-2025-59943?
The phpMyFAQ application is susceptible to an email registration issue that does not enforce unique email addresses during user account creation. This vulnerability enables an attacker to create multiple accounts using the same email address, leading to confusion in identifying user accounts. Since email serves as a primary means for password resets and notifications, this flaw can facilitate unauthorized access to user accounts, potentially escalating privileges or allowing account takeover in certain scenarios. The issue has been resolved in version 4.0.13.
Affected Version(s)
phpMyFAQ >= 4.0.7, < 4.0.13