CyberRota Analysis
AI-GeneratedThe vulnerability affects phpMyFAQ versions prior to 4.1.6, allowing authenticated administrators with specific privileges to execute arbitrary PHP code. By exploiting the configuration API, attackers can upload a malicious ZIP file, manipulate the upgrade settings, and extract it to the application root, leading to potential compromise of the web server. Organizations using phpMyFAQ should prioritize this issue to mitigate the risk of unauthorized code execution.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated administrators with CONFIGURATION_EDIT and ATTACHMENT_ADD privileges to write arbitrary PHP files by manipulating the upgrade.lastDownloadedPackage setting. Attackers can upload a malicious ZIP file as an attachment, point the updater configuration to its stored path, and extract it into the application root to achieve code execution as the web server user.