Executive brief
phpMyFAQ is an open-source FAQ software used to manage and publish knowledge bases. A security flaw allows unauthorized individuals to bypass access controls and view the titles of private or restricted FAQ entries. This could lead to the exposure of sensitive internal information, such as project names or confidential topics, even if the full content of the articles remains protected.
Technical details
An information disclosure vulnerability exists in phpMyFAQ's getIdFromSolutionId() method due to a lack of permission filtering. The /solution_id_{id}.html route uses this method to resolve solution IDs to internal IDs and titles, then issues a 301 redirect to a slugified URL. Because the method does not check if the FAQ is restricted to specific users or groups, an unauthenticated attacker can sequentially iterate through solution IDs to discover restricted entries. The sensitive metadata, specifically the FAQ title, is leaked through the Location header of the redirect and page canonical links. This issue is fixed in version 4.1.2.
Affected products
- thorsten phpMyFAQ < 4.1.2
Timeline
- 2026-04-28: advisory: Original vendor advisory published (GHSA-99qv-g4x9-mgc3)
- 2026-05-15: disclosed: CVE-2026-46366 published
- 2026-06-08: other: Advisory GHSA-cqrw-j4qc-7f9w withdrawn as a duplicate