CyberRota Analysis
AI-GeneratedphpMyFAQ versions prior to 4.1.7 are vulnerable due to the storage of password reset tokens in a publicly accessible tracking file when user tracking is enabled. This flaw allows unauthenticated attackers to access the tracking file and extract tokens, enabling them to exploit the password reset functionality and potentially take over user accounts. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized account access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file at content/core/data/trackingDDMMYYYY to extract reset tokens and replay them against the password reset API to take over user accounts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)