Impact
phpMyFAQ versions before 4.1.7 do not enforce the CONFIGURATION_EDIT permission on certain admin API read endpoints. As a result, any authenticated user can query the LDAP, Elasticsearch, OpenSearch, and dashboard configuration APIs and obtain detailed administrative data such as LDAP server topology, bind account names, search bases, index statistics, and site analytics. This flaw permits disclosure of sensitive configuration information, potentially aiding attackers in planning further attacks or profiling the environment.
Affected Systems
Thorsten phpMyFAQ installations running any version earlier than 4.1.7 are vulnerable. The issue affects the admin APIs exposed by the phpMyFAQ application when accessed by authenticated users. Users should verify the version of phpMyFAQ deployed in their environments and confirm that it is at least 4.1.7.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitation requires an already authenticated session; the attacker needs valid credentials or a session cookie. The EPSS score of 0.00204 (less than 1%) indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the information disclosed could be valuable to anyone who gains login access, so repairs should be applied promptly to prevent unnecessary exposure.
OpenCVE Enrichment