CVE-2025-59943

HIGH

Phpmyfaq < 4.0.13 - Improper Access Control

Title source: rule
STIX 2.1

Description

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13.

Scores

CVSS v3 8.1
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-284 CWE-286
Status published
Products (2)
phpmyfaq/phpmyfaq 4.0.7
thorsten/phpmyfaq 4.0.7 - 4.0.13Packagist
Published Oct 03, 2025
Tracked Since Feb 18, 2026