phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request.
References
Configurations
No configuration.
History
30 May 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-xvp4-phqj-cjr3 - |
28 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 16:16
Updated : 2026-05-30 02:16
NVD link : CVE-2026-35671
Mitre link : CVE-2026-35671
CVE.ORG link : CVE-2026-35671
JSON object : View
Products Affected
No product.
CWE
CWE-266
Incorrect Privilege Assignment
