Executive brief
phpMyFAQ, an open-source FAQ software, contains a flaw in its password reset process. An attacker can reset any user's password, including administrators, simply by knowing their username and email address. This allows for a complete takeover of the system, potentially leading to the theft of sensitive data or the modification of public-facing information.
Technical details
An authentication bypass vulnerability exists in phpMyFAQ's API endpoint `/api/user/password/update`. The `updatePassword()` method in `UnauthorizedUserController.php` processes PUT requests containing only a username and email without requiring a cryptographic reset token or performing any secondary verification. Because the endpoint also lacks rate limiting, an attacker can enumerate valid username/email pairs and trigger an immediate password reset. The system then generates a new plaintext password and sends it to the user's email, effectively locking out the original user and allowing the attacker to take over the account if they can access the email or if the reset itself is the goal of a denial-of-service attack. The vulnerability is patched in version 4.1.3.
Affected products
- thorsten phpMyFAQ < 4.1.3
Timeline
- 2026-05-14: disclosed
- 2026-05-20: advisory
- 2026-05-20: patched: Patched in version 4.1.3
References
- https://api.github.com/users/cyberHunter127
- https://github.com/cyberHunter127
- https://api.github.com/users/cyberHunter127/gists%7B/gist_id%7D
- https://api.github.com/users/cyberHunter127/repos
- https://avatars.githubusercontent.com/u/48629367?v=4
- https://api.github.com/users/cyberHunter127/events%7B/privacy%7D