OSV 1.4.0 · unreviewed · 修改于 2026-09-04 20:30
发布时间
2026-09-04 20:30
GitHub 审查时间
—
NVD 发布时间
2026-09-04 20:17
源文件
advisories/unreviewed/2026/09/GHSA-39j8-x5gv-w8w5/GHSA-39j8-x5gv-w8w5.json
phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints searches and content-health that enforce only authentication without permission checks. Any authenticated user can access these endpoints to read site-wide search statistics and content-health counters regardless of their privilege level.
该公告没有提供结构化的受影响软件包信息。