Path Traversal Vulnerability in phpMyFAQ by phpMyFAQ Team
CVE-2026-66397
8.6HIGH
What is CVE-2026-66397?
In phpMyFAQ prior to version 4.1.6, insufficient validation of path traversal sequences in the existing_image field during category updates poses a significant security risk. Authenticated attackers could exploit this vulnerability to delete arbitrary files, such as the database.php configuration file, by taking advantage of inadequate sanitization in the Image::delete() function. This could lead to unauthorized access to the setup wizard, enabling the creation of new superadmin accounts and compromising the integrity of the installation.
Affected Version(s)
phpMyFAQ 0 < 4.1.6
phpMyFAQ 4.1.6
