<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T10:06:27.476375+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329548</id>
    <title>EUVD-2026-329548</title>
    <updated>2026-10-09T10:06:27.529273+00:00</updated>
    <content>EUVD-2026-329548</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35671</id>
    <title>fkie_cve-2026-35671</title>
    <updated>2026-10-09T10:06:27.529313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without authorization verification. An attacker with low-privilege admin credentials can escalate to SuperAdmin by modifying the userId parameter in the overwrite-password API request.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xvp4-phqj-cjr3</id>
    <title>GHSA-xvp4-phqj-cjr3 — phpMyFAQ: IDOR Account Takeover</title>
    <updated>2026-10-09T10:06:27.529349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq</p>
<p>### Summary
An Insecure Direct Object Reference (IDOR) vulnerability in phpMyFAQ's Admin API allows any authenticated administrator to change the password of any user account, including SuperAdmin accounts (userId=1), without authorization verification. An attacker with a low-privilege admin account can escalate privileges to full SuperAdmin control by simply changing the target user's ID in the API request body.</p>
<p>### Details
File: phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/UserController.php
Lines: 232-271
The overwritePassword() method at line 232 accepts PUT requests to /admin/api/user/overwrite-password:
#[Route(path: 'user/overwrite-password', name: 'admin.api.user.overwrite-password', methods: ['PUT'])]
```php
public function overwritePassword(Request $request): JsonResponse
{
    $this-&gt;userHasUserPermission();  // Only checks if user has USER_EDIT permission
    $currentUser = CurrentUser::getCurrentUser($this-&gt;configuration);
    $data = json_decode($request-&gt;getContent());
    $userId = Filter::filterVar($data-&gt;userId, FILTER_VALIDATE_INT);  // User-controlled!
    $csrfToken = Filter::filterVar($data-&gt;csrf, FILTER_SANITIZE_SPECIAL_CHARS);
    $newPassword = Filter::filterVar($data-&gt;newPassword, FILTER_SANITIZE_SPECIAL_CHARS);
    $retypedPassword = Filter::filterVar($data-&gt;passwordRepeat, FILTER_SANITIZE_SPECIAL_CHARS);
    if (!Token::getInstance($this-&gt;session)-&gt;verifyToken(page: 'overwrite-password', requestToken: $csrfToken)) {
        return $this-&gt;j…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xvp4-phqj-cjr3"/>
  </entry>
</feed>
