CVE-2026-66397

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attackers to delete arbitrary files by exploiting insufficient sanitization in Image::delete(). Attackers can delete the database.php configuration file to disable the installation gate and access the public setup wizard to create new superadmin accounts.
CVSS

No CVSS.

Configurations

No configuration.

History

27 Jul 2026, 19:17

Type Values Removed Values Added
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mh9w-5hr8-3272 - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-mh9w-5hr8-3272 -

27 Jul 2026, 16:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-27 16:18

Updated : 2026-07-28 20:37


NVD link : CVE-2026-66397

Mitre link : CVE-2026-66397

CVE.ORG link : CVE-2026-66397


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')