Impact
phpMyFAQ versions before 4.1.8 do not validate the CAPTCHA field when the "store" parameter is set to "now" in question submission requests. This flaw permits unauthenticated users to circumvent the CAPTCHA protection and submit unlimited questions to the system. The resulting database pollution can lead to excessive storage consumption, and each accepted question triggers outgoing email notifications, potentially resulting in spam or denial of service through message flooding.
Affected Systems
The vulnerability affects the phpMyFAQ application provided by thorsten. Any instance running a version earlier than 4.1.8 is susceptible. The affected product is commonly deployed in web forums and knowledge bases where users can submit questions.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate to high severity. While an explicit EPSS score is not available, the vulnerability is exploitable remotely via standard HTTP requests without authentication. The vendor has not listed it in the CISA KEV catalog, but the potential for widespread spam emails and database corruption makes it a significant risk for organizations running vulnerable installations.
OpenCVE Enrichment