Impact
The vulnerability is a missing self‑rights constraint in the GroupController::updatePermissions method within phpMyFAQ. Administrators with GROUP_EDIT privileges can allocate any permissions to a group, regardless of whether they personally hold those permissions. As a result, an attacker who can become a delegated administrator can grant high‑value permissions to a group they belong to and inherit those capabilities, effectively escalating their privileges to full administrative control.
Affected Systems
phpMyFAQ before 4.1.5 is affected. The vulnerable component is the GroupController within the phpMyFAQ application. All installations of phpMyFAQ version 4.1.4 and earlier are susceptible to this escalation path.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of this privilege escalation. The EPSS score is not available, suggesting limited publicly available exploitation data at this time. The vulnerability is not listed in CISA KEV. Exploitation requires access to a GROUP_EDIT role and the ability to edit group permissions; it is therefore a local or internal attack vector. Once exploited, an attacker can assign themselves powerful rights, compromising the entire application.
OpenCVE Enrichment