Path Traversal Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-66397

8.6HIGH

Key Information:

Vendor

Thorsten

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-66397?

In phpMyFAQ prior to version 4.1.6, insufficient validation of path traversal sequences in the existing_image field during category updates poses a significant security risk. Authenticated attackers could exploit this vulnerability to delete arbitrary files, such as the database.php configuration file, by taking advantage of inadequate sanitization in the Image::delete() function. This could lead to unauthorized access to the setup wizard, enabling the creation of new superadmin accounts and compromising the integrity of the installation.

Affected Version(s)

phpMyFAQ 0 < 4.1.6

phpMyFAQ 4.1.6

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ImDuong
.