<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:24:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322439</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322439</link>
      <description>EUVD-2026-322439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322439</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46366</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46366</link>
      <description>&lt;p&gt;phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially iterate solution IDs to discover all FAQs including those restricted to specific users or groups, leaking sensitive metadata through redirect Location headers and page canonical links.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks permission filtering, allowing unauthenticated attackers to enumerate restricted FAQ entries and read their titles via the /solution_id_{id}.html endpoint. Attackers can sequentially iterate solution IDs to discover all FAQs including those restricted to specific users or groups, leaking sensitive metadata through redirect Location headers and page canonical links.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46366</guid>
    </item>
    <item>
      <title>GHSA-99qv-g4x9-mgc3 — phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-99qv-g4x9-mgc3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The public `/solution_id_{id}.html` route calls `Faq::getIdFromSolutionId()` in `phpmyfaq/src/phpMyFAQ/Faq.php:1312`. That query joins `faqdata` with `faqcategoryrelations` solely by `solution_id` and returns the matching FAQ&amp;#39;s `id`, `lang`, `thema` (title), and `category_id` with no permission filter. An unauthenticated visitor hits the route with a sequential integer and the server 301-redirects to `/content/&amp;lt;category&amp;gt;/&amp;lt;id&amp;gt;/&amp;lt;lang&amp;gt;/&amp;lt;title-slug&amp;gt;.html`, leaking the FAQ&amp;#39;s existence, internal id, language, category binding, and title via the redirect&amp;#39;s `Location` header and the redirected page&amp;#39;s canonical link, share-to-social URLs, and hidden form fields. The related `getFaqBySolutionId()` at line 1221 contains an explicit fallback query (added &amp;#34;for tests&amp;#34;) that also bypasses the permission filter, widening the blast radius to any callsite that trusts its result.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### The sink: `getIdFromSolutionId()` has no permission filter&lt;/p&gt;
&lt;p&gt;`phpmyfaq/src/phpMyFAQ/Faq.php:1312`:&lt;/p&gt;
&lt;p&gt;```php
public function getIdFromSolutionId(int $solutionId): array
{
    $query = sprintf(
        &amp;#39;SELECT fd.id, fd.lang, fd.thema AS question, fd.content, fcr.category_id
         FROM %sfaqdata fd
         LEFT JOIN %sfaqcategoryrelations fcr
           ON fd.id = fcr.record_id AND fd.lang = fcr.record_lang
         WHERE fd.solution_id = %d&amp;#39;,
        Database::getTablePrefix(),
        Database::getTablePrefix(),
        $solutionId,
    );
    // ...
}
```&lt;/p&gt;
&lt;p&gt;No `WHERE`-clause permission f…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: thorsten/phpmyfaq, Packagist: phpmyfaq/phpmyfaq&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The public `/solution_id_{id}.html` route calls `Faq::getIdFromSolutionId()` in `phpmyfaq/src/phpMyFAQ/Faq.php:1312`. That query joins `faqdata` with `faqcategoryrelations` solely by `solution_id` and returns the matching FAQ&amp;#39;s `id`, `lang`, `thema` (title), and `category_id` with no permission filter. An unauthenticated visitor hits the route with a sequential integer and the server 301-redirects to `/content/&amp;lt;category&amp;gt;/&amp;lt;id&amp;gt;/&amp;lt;lang&amp;gt;/&amp;lt;title-slug&amp;gt;.html`, leaking the FAQ&amp;#39;s existence, internal id, language, category binding, and title via the redirect&amp;#39;s `Location` header and the redirected page&amp;#39;s canonical link, share-to-social URLs, and hidden form fields. The related `getFaqBySolutionId()` at line 1221 contains an explicit fallback query (added &amp;#34;for tests&amp;#34;) that also bypasses the permission filter, widening the blast radius to any callsite that trusts its result.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### The sink: `getIdFromSolutionId()` has no permission filter&lt;/p&gt;
&lt;p&gt;`phpmyfaq/src/phpMyFAQ/Faq.php:1312`:&lt;/p&gt;
&lt;p&gt;```php
public function getIdFromSolutionId(int $solutionId): array
{
    $query = sprintf(
        &amp;#39;SELECT fd.id, fd.lang, fd.thema AS question, fd.content, fcr.category_id
         FROM %sfaqdata fd
         LEFT JOIN %sfaqcategoryrelations fcr
           ON fd.id = fcr.record_id AND fd.lang = fcr.record_lang
         WHERE fd.solution_id = %d&amp;#39;,
        Database::getTablePrefix(),
        Database::getTablePrefix(),
        $solutionId,
    );
    // ...
}
```&lt;/p&gt;
&lt;p&gt;No `WHERE`-clause permission f…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-99qv-g4x9-mgc3</guid>
    </item>
  </channel>
</rss>
