<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:51:45 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329551</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329551</link>
      <description>EUVD-2026-329551</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329551</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35676</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35676</link>
      <description>&lt;p&gt;phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Attackers can enumerate valid username and email pairs and force immediate password changes by sending PUT requests to the /api/index.php/user/password/update endpoint, causing account disruption and invalidating legitimate user credentials.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35676</guid>
    </item>
    <item>
      <title>GHSA-9qv9-8xv6-5p35 — phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Vali…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9qv9-8xv6-5p35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The password reset API can be triggered without authentication and without any out-of-band confirmation step.&lt;/p&gt;
&lt;p&gt;If an attacker knows a valid `username + email` pair, they can call the reset endpoint directly. The application immediately generates a new password, writes it to the account, and only then sends the new password by email.&lt;/p&gt;
&lt;p&gt;This creates two issues at the same time:&lt;/p&gt;
&lt;p&gt;- account enumeration through the response difference between valid and invalid pairs
- forced password reset of another user&amp;#39;s account, which invalidates the old password immediately&lt;/p&gt;
&lt;p&gt;In my local reproduction, I confirmed both the response difference and the password change itself.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The relevant code is in `phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php`.&lt;/p&gt;
&lt;p&gt;The route is exposed without authentication:&lt;/p&gt;
&lt;p&gt;```php
#[Route(path: &amp;#39;user/password/update&amp;#39;, name: &amp;#39;api.private.user.password&amp;#39;, methods: [&amp;#39;PUT&amp;#39;])]
public function updatePassword(Request $request): JsonResponse
```&lt;/p&gt;
&lt;p&gt;The flow is straightforward:&lt;/p&gt;
&lt;p&gt;```php
$loginExist = $user-&amp;gt;getUserByLogin($username);&lt;/p&gt;
&lt;p&gt;if ($loginExist &amp;amp;&amp;amp; $email === $user-&amp;gt;getUserData(&amp;#39;email&amp;#39;)) {
    $newPassword = $user-&amp;gt;createPassword();
    $user-&amp;gt;changePassword($newPassword);
    $mail-&amp;gt;send();
    return $this-&amp;gt;json([&amp;#39;success&amp;#39; =&amp;gt; Translation::get(key: &amp;#39;lostpwd_mail_okay&amp;#39;)], Response::HTTP_OK);
}&lt;/p&gt;
&lt;p&gt;return $this-&amp;gt;json([&amp;#39;error&amp;#39; =&amp;gt; Translation::get(key: &amp;#39;lostpwd_err_1&amp;#39;)], Response::HTTP_CONFLICT);
```&lt;/p&gt;
&lt;p&gt;The core issue is that the passw…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The password reset API can be triggered without authentication and without any out-of-band confirmation step.&lt;/p&gt;
&lt;p&gt;If an attacker knows a valid `username + email` pair, they can call the reset endpoint directly. The application immediately generates a new password, writes it to the account, and only then sends the new password by email.&lt;/p&gt;
&lt;p&gt;This creates two issues at the same time:&lt;/p&gt;
&lt;p&gt;- account enumeration through the response difference between valid and invalid pairs
- forced password reset of another user&amp;#39;s account, which invalidates the old password immediately&lt;/p&gt;
&lt;p&gt;In my local reproduction, I confirmed both the response difference and the password change itself.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The relevant code is in `phpmyfaq/src/phpMyFAQ/Controller/Frontend/Api/UnauthorizedUserController.php`.&lt;/p&gt;
&lt;p&gt;The route is exposed without authentication:&lt;/p&gt;
&lt;p&gt;```php
#[Route(path: &amp;#39;user/password/update&amp;#39;, name: &amp;#39;api.private.user.password&amp;#39;, methods: [&amp;#39;PUT&amp;#39;])]
public function updatePassword(Request $request): JsonResponse
```&lt;/p&gt;
&lt;p&gt;The flow is straightforward:&lt;/p&gt;
&lt;p&gt;```php
$loginExist = $user-&amp;gt;getUserByLogin($username);&lt;/p&gt;
&lt;p&gt;if ($loginExist &amp;amp;&amp;amp; $email === $user-&amp;gt;getUserData(&amp;#39;email&amp;#39;)) {
    $newPassword = $user-&amp;gt;createPassword();
    $user-&amp;gt;changePassword($newPassword);
    $mail-&amp;gt;send();
    return $this-&amp;gt;json([&amp;#39;success&amp;#39; =&amp;gt; Translation::get(key: &amp;#39;lostpwd_mail_okay&amp;#39;)], Response::HTTP_OK);
}&lt;/p&gt;
&lt;p&gt;return $this-&amp;gt;json([&amp;#39;error&amp;#39; =&amp;gt; Translation::get(key: &amp;#39;lostpwd_err_1&amp;#39;)], Response::HTTP_CONFLICT);
```&lt;/p&gt;
&lt;p&gt;The core issue is that the passw…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9qv9-8xv6-5p35</guid>
    </item>
  </channel>
</rss>
