Path Traversal Vulnerability in phpMyFAQ Software by phpMyFAQ
CVE-2026-45008

6.5MEDIUM

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
15 May 2026

What is CVE-2026-45008?

phpMyFAQ versions prior to 4.1.2 are susceptible to a path traversal vulnerability within the Client::deleteClientFolder function. This flaw permits attackers, once they possess the INSTANCE_DELETE permission, to construct malicious URLs that leverage traversal sequences (e.g., https://../../../) to delete arbitrary directories outside the designated client folder structure. This could potentially lead to unauthorized deletions and serious data loss for users.

Affected Version(s)

phpmyfaq 0 < 4.1.2

phpmyfaq 4.1.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

adrgs
aisafe-bot
.