Impact
phpMyFAQ versions prior to 4.1.7 issue remember‑me cookies before the two‑factor authentication (2FA) challenge has finished. An attacker who already has valid user credentials can capture the cookie, skip the second‑factor prompt, and replay it to gain full authenticated access without completing 2FA. The vulnerability allows abuse of the authentication mechanism, effectively lifting the protection provided by 2FA.
Affected Systems
The flaw affects the phpMyFAQ application published by the developer thorsten for all releases before version 4.1.7.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as high severity; the EPSS score indicates less than 1%, suggesting a very low exploitation probability. It is not listed in the CISA KEV catalog. Attackers would need legitimate user credentials and the ability to observe or capture the remember‑me cookie, typically through in‑network packet capture or by exploiting a compromised client. Once a cookie is obtained, no additional authentication is required, allowing unrestricted access to the system.
OpenCVE Enrichment