phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin content pages, allowing lesser-privileged editors to read draft and inactive content. Attackers with only add permissions can access news edit and FAQ translate endpoints to view unpublished content invisible to the public.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 12:17
Updated : 2026-09-08 20:05
NVD link : CVE-2026-85587
Mitre link : CVE-2026-85587
CVE.ORG link : CVE-2026-85587
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
