Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2wjp-w7g7-h63q: thorsten/phpmyfaq vulnerable to improper access control

thorsten/phpmyfaq prior to 3.1.12 is vulnerable to improper access control when FAQ News is marked as inactive in settings and have comments enabled, allowing comments to be posted on inactive FAQs. This has been fixed in 3.1.12.

ghsa
#git#php

thorsten/phpmyfaq vulnerable to improper access control

Moderate severity GitHub Reviewed Published Apr 5, 2023 to the GitHub Advisory Database • Updated Apr 6, 2023

Related news

CVE-2023-1883: fix: added check if news or FAQs are active · thorsten/phpMyFAQ@db77df8

Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.