phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including database credentials. Unauthenticated attackers can race concurrent requests to download the temporary ZIP file before deletion, or exploit XSS in admin contexts to trigger authenticated backups and retrieve the archive.
References
| Link | Resource |
|---|---|
| https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-8hmh-mrx6-pqvf | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/phpmyfaq-before-information-disclosure-via-backup-zip | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-19 14:17
Updated : 2026-09-01 16:05
NVD link : CVE-2026-75920
Mitre link : CVE-2026-75920
CVE.ORG link : CVE-2026-75920
JSON object : View
Products Affected
phpmyfaq
- phpmyfaq
CWE
CWE-377
Insecure Temporary File
