Email Registration Flaw in phpMyFAQ Application by Thorsten
CVE-2025-59943
What is CVE-2025-59943?
The phpMyFAQ application is susceptible to an email registration issue that does not enforce unique email addresses during user account creation. This vulnerability enables an attacker to create multiple accounts using the same email address, leading to confusion in identifying user accounts. Since email serves as a primary means for password resets and notifications, this flaw can facilitate unauthorized access to user accounts, potentially escalating privileges or allowing account takeover in certain scenarios. The issue has been resolved in version 4.0.13.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
phpMyFAQ >= 4.0.7, < 4.0.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
