CVE-2024-28107

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in the `insertentry` & `saveentry` when modifying records due to improper escaping of the email address. This allows any authenticated user with the rights to add/edit FAQ news to exploit this vulnerability to exfiltrate data, take over accounts and in some cases, even achieve RCE. This vulnerability is fixed in 3.2.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmyfaq:phpmyfaq:3.2.5:*:*:*:*:*:*:*

History

09 Jan 2025, 17:01

Type Values Removed Values Added
First Time Phpmyfaq
Phpmyfaq phpmyfaq
CPE cpe:2.3:a:phpmyfaq:phpmyfaq:3.2.5:*:*:*:*:*:*:*
References () https://github.com/thorsten/phpMyFAQ/commit/d0fae62a72615d809e6710861c1a7f67ac893007 - () https://github.com/thorsten/phpMyFAQ/commit/d0fae62a72615d809e6710861c1a7f67ac893007 - Patch
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-2grw-mc9r-822r - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-2grw-mc9r-822r - Exploit, Vendor Advisory

21 Nov 2024, 09:05

Type Values Removed Values Added
References () https://github.com/thorsten/phpMyFAQ/commit/d0fae62a72615d809e6710861c1a7f67ac893007 - () https://github.com/thorsten/phpMyFAQ/commit/d0fae62a72615d809e6710861c1a7f67ac893007 -
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-2grw-mc9r-822r - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-2grw-mc9r-822r -

26 Mar 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) phpMyFAQ es una aplicación web de preguntas frecuentes de código abierto para PHP 8.1+ y MySQL, PostgreSQL y otras bases de datos. Se ha descubierto una vulnerabilidad de inyección SQL en `insertentry` y `saveentry` al modificar registros debido a un escape inadecuado de la dirección de correo electrónico. Esto permite que cualquier usuario autenticado con derechos para agregar/editar noticias de preguntas frecuentes aproveche esta vulnerabilidad para filtrar datos, hacerse cargo de cuentas y, en algunos casos, incluso lograr RCE. Esta vulnerabilidad se soluciona en 3.2.6.

25 Mar 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-25 19:15

Updated : 2025-01-09 17:01


NVD link : CVE-2024-28107

Mitre link : CVE-2024-28107

CVE.ORG link : CVE-2024-28107


JSON object : View

Products Affected

phpmyfaq

  • phpmyfaq
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')