Executive brief
phpMyFAQ is a popular open-source FAQ management system that allows website visitors to submit questions anonymously through a web interface. A vulnerability allows attackers to bypass CAPTCHA protections and submit unlimited fake questions without authentication, causing database pollution and causing the system to send unwanted email notifications to arbitrary addresses, effectively using the victim's mail server as a relay.
Technical details
The vulnerability is a logic flaw in the CAPTCHA validation control (CWE-799: Improper Control of Interaction Frequency). When an anonymous user submits a question with the "store" parameter set to "now", the server skips CAPTCHA validation entirely, intended for a two-phase UX workflow but never enforced on the server side. The endpoint lacks CSRF token protection and accepts arbitrary attacker-supplied email addresses. An unauthenticated attacker can send a simple POST request to the question submission endpoint with store=now to bypass all validation and spam the system; each submission triggers an outgoing mail notification, potentially relaying emails to attacker-chosen recipients. The vulnerability affects phpMyFAQ versions before 4.1.8 when main.enableAskQuestions=true and records.allowQuestionsForGuests=true (default settings).
Affected products
- phpMyFAQ phpMyFAQ before 4.1.8
Timeline
- 2026-08-20: disclosed: GitHub Security Advisory (GHSA-72vj-pvm4-mm7x) published
- 2026-09-04: advisory: CVE-2026-85586 published on NVD