Headline
GHSA-2wjp-w7g7-h63q: thorsten/phpmyfaq vulnerable to improper access control
thorsten/phpmyfaq prior to 3.1.12 is vulnerable to improper access control when FAQ News is marked as inactive in settings and have comments enabled, allowing comments to be posted on inactive FAQs. This has been fixed in 3.1.12.
thorsten/phpmyfaq vulnerable to improper access control
Moderate severity GitHub Reviewed Published Apr 5, 2023 to the GitHub Advisory Database • Updated Apr 6, 2023
Related news
CVE-2023-1883: fix: added check if news or FAQs are active · thorsten/phpMyFAQ@db77df8
Improper Access Control in GitHub repository thorsten/phpmyfaq prior to 3.1.12.