<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:47:29.604336+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329551</id>
    <title>EUVD-2026-329551</title>
    <updated>2026-10-06T06:47:29.648838+00:00</updated>
    <content>EUVD-2026-329551</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329551"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35676</id>
    <title>fkie_cve-2026-35676</title>
    <updated>2026-10-06T06:47:29.648875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9qv9-8xv6-5p35</id>
    <title>GHSA-9qv9-8xv6-5p35 — phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Vali…</title>
    <updated>2026-10-06T06:47:29.648907+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq</p>
<p>### Summary</p>
<p>The password reset API can be triggered without authentication and without any out-of-band confirmation step.</p>
<p>If an attacker knows a valid `username + email` pair, they can call the reset endpoint directly. The application immediately generates a new password, writes it to the account, and only then sends the new password by email.</p>
<p>This creates two issues at the same time:</p>
<p>- account enumeration through the response difference between valid and invalid pairs
- forced password reset of another user's account, which invalidates the old password immediately</p>
<p>In my local reproduction, I confirmed both the response difference and the password change itself.</p>
<p>### Details</p>
<p>The relevant code is in `phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php`.</p>
<p>The route is exposed without authentication:</p>
<p>```php
#[Route(path: 'user/password/update', name: 'api.private.user.password', methods: ['PUT'])]
public function updatePassword(Request $request): JsonResponse
```</p>
<p>The flow is straightforward:</p>
<p>```php
$loginExist = $user-&gt;getUserByLogin($username);</p>
<p>if ($loginExist &amp;&amp; $email === $user-&gt;getUserData('email')) {
    $newPassword = $user-&gt;createPassword();
    $user-&gt;changePassword($newPassword);
    $mail-&gt;send();
    return $this-&gt;json(['success' =&gt; Translation::get(key: 'lostpwd_mail_okay')], Response::HTTP_OK);
}</p>
<p>return $this-&gt;json(['error' =&gt; Translation::get(key: 'lostpwd_err_1')], Response::HTTP_CONFLICT);
```</p>
<p>The core issue is that the passw…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9qv9-8xv6-5p35"/>
  </entry>
</feed>
