Executive brief
phpMyFAQ is an open-source FAQ software platform. A security flaw in its administrative interface allows any logged-in user, even those with no administrative rights, to access restricted management pages. This could lead to the exposure of sensitive information such as user data, system configurations, and administrative logs.
Technical details
An authorization bypass exists in phpMyFAQ's AbstractAdministrationController::userHasPermission() method. When a permission check fails, the controller catches the resulting ForbiddenException and sends a 'forbidden' response to the client but fails to terminate PHP execution (e.g., via exit or return). Consequently, the calling controller method continues to execute, fetching protected data and rendering the full administrative template. The final response sent to the user contains both the 'forbidden' message and the sensitive administrative content appended afterward. This affects 58 different admin controllers, exposing logs, user management, and system configuration. The issue is resolved in version 4.1.2.
Affected products
- thorsten phpMyFAQ < 4.1.2
Timeline
- 2026-04-28: advisory: Original advisory GHSA-hpgw-ww76-c68r published by vendor
- 2026-05-15: disclosed: CVE-2026-46362 published
- 2026-06-09: patched: Duplicate advisory GHSA-w9mj-gfrm-hj5x withdrawn in favor of original report