CyberRota Analysis
AI-GeneratedThe admin dashboard API endpoints in phpMyFAQ versions prior to 4.2.0-alpha.2 are vulnerable due to a missing authorization check, allowing any authenticated user to access sensitive site-wide search statistics and content-health counters without appropriate permissions. This could lead to unauthorized information disclosure, potentially compromising the integrity of the application. Organizations using phpMyFAQ should prioritize patching this vulnerability to safeguard their data and maintain user privacy.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters regardless of their privilege level.