CVE-2026-45007: Thorsten Phpmyfaq

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIsAuthenticated() instead of userHasPermission(CONFIGURATION_EDIT). Any authenticated user can enumerate system configuration metadata including permission model, cache backend, mail provider, and translation provider by querying /admin/api/configuration endpoints, violating least privilege access control.

Affected products

  • Thorsten Phpmyfaq: before 4.1.2 (fixed in 4.1.2)

Published 2026-05-15. Last modified 2026-06-17.