Impact
phpMyFAQ versions prior to 4.1.6 are vulnerable to a path traversal attack triggered during category image deletion. An authenticated user can supply a path that resolves outside the intended directory, enabling them to delete any file on the system. By targeting the configuration file that controls the installation gate, an attacker can remove it and trigger the public setup wizard, which then allows the creation of new superadmin accounts. The vulnerability is an input validation weakness classified as CWE‑22.
Affected Systems
All installations of phpMyFAQ that are version 4.1.5 or earlier, produced by Thorsten, are affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, indicating high severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a valid authenticated account, after which arbitrary files can be removed, compromising confidentiality, integrity and availability, and enabling the attacker to gain full administrative control through the setup wizard.
OpenCVE Enrichment