<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T09:20:51.436959+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329549</id>
    <title>EUVD-2026-329549</title>
    <updated>2026-10-10T09:20:51.483865+00:00</updated>
    <content>EUVD-2026-329549</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329549"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35672</id>
    <title>fkie_cve-2026-35672</title>
    <updated>2026-10-10T09:20:51.483904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers can send an empty x-pmf-token header to bypass token validation and inject malicious content via POST endpoints /api/v4.0/faq/create, /api/v4.0/category, and /api/v4.0/question.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gp95-j463-vv28</id>
    <title>GHSA-gp95-j463-vv28 — phpMyFAQ: Default Empty API Token Authentication Bypass</title>
    <updated>2026-10-10T09:20:51.483938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq</p>
<p>### Summary</p>
<p>A default empty API client token allows any unauthenticated user to create and modify FAQ entries, categories, and questions via the REST API. The vulnerability exists in all versions since API v4.0 was introduced because the installation process seeds `api.apiClientToken` with an empty string, and the `hasValidToken()` comparison logic cannot distinguish between "no token configured" and "attacker sent a matching empty token header."</p>
<p>### Details</p>
<p>The root cause is in two files:</p>
<p>**1. Installation default** (`src/phpMyFAQ/Setup/Installation/DefaultDataSeeder.php`, line 277-278):</p>
<p>```php
'api.enableAccess'   =&gt; 'true',
'api.apiClientToken' =&gt; '',       // ← defaults to empty string
```</p>
<p>**2. Authentication check** (`src/phpMyFAQ/Controller/AbstractController.php`, line 198-204):</p>
<p>```php
protected function hasValidToken(): void
{
    $request = Request::createFromGlobals();
    if ($this-&gt;configuration-&gt;get('api.apiClientToken') !== $request-&gt;headers-&gt;get('x-pmf-token')) {
        throw new UnauthorizedHttpException('"x-pmf-token" is not valid.');
    }
}
```</p>
<p>The method uses strict inequality (`!==`). When `api.apiClientToken` is `''` (default) and the attacker sends `x-pmf-token: ` (empty header value), the comparison becomes `'' !== ''` which evaluates to `false` — no exception is thrown, and authentication is completely bypassed.</p>
<p>The OpenAPI annotations confirm the developer intended these endpoints to require authentication: write endpoints are tagged `'End…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gp95-j463-vv28"/>
  </entry>
</feed>
