Description
phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermission() that fails to terminate execution after sending a forbidden response. Attackers can access all permission-protected admin pages by requesting their URLs as authenticated users, exposing admin logs, user data, system information, and application configuration.
Problem types
Product status
Any version before 4.1.2
4.1.2 (semver)
Credits
offset
References
github.com/...pMyFAQ/security/advisories/GHSA-hpgw-ww76-c68r (GHSA Advisory GHSA-hpgw-ww76-c68r)
www.vulncheck.com/...es-via-non-terminating-permission-check (VulnCheck Advisory: phpMyFAQ - Authorization Bypass in Admin Pages via Non-Terminating Permission Check)