Listen to this Post
A vulnerability in phpMyFAQ versions 4.1.0 through 4.1.4 allows unauthenticated access to inactive (draft or review-only) FAQ content through public API endpoints. The issue stems from an inconsistent application of the `active = ‘yes’` filter across different API routes.
In phpMyFAQ 4.1.4, while the `GET /api/v3.1/faqs/{categoryId}` endpoint correctly hides inactive FAQs, two other public API endpoints do not. The `GET /api/v3.1/faq/{categoryId}/{faqId}` endpoint returns the full and answer of an inactive FAQ. Similarly, the `GET /api/v3.1/faqs/tags/{tagId}` and `GET /api/v4.0/faqs/tags/{tagId}` endpoints return the inactive FAQ’s and a preview of its answer.
This occurs because the `FaqController::getByTagId()` method retrieves FAQ IDs via `Tags::getFaqsByTagId()` and then calls Faq::getFaqsByIds(). The `Faq::getFaqsByIds()` method filters by record ID, language, and permission, but critically, it does not filter by the `active` status or publication date windows. This allows it to return the s and previews of inactive FAQs. The vulnerability is fixed in version 4.1.5.
DailyCVE Form:
Platform: phpMyFAQ
Version: 4.1.0-4.1.4
Vulnerability: Info Disclosure
Severity: Medium
Date: 2026-07-10
Prediction: Already Patched (4.1.5)
What Undercode Say:
Analytics & Commands
The following bash commands can be used to reproduce the vulnerability locally, as demonstrated in the official proof-of-concept (PoC).
Navigate to the phpMyFAQ 4.1.4 source directory cd /path/to/phpMyFAQ-4.1.4 Ensure dependencies are installed composer install Run the PoC script php path/to/poc_phpmyfaq_414_inactive_faq_api_exposure.php /path/to/phpMyFAQ-4.1.4
The expected output from a successful reproduction is:
VERDICT: reproduced inactive FAQ exposure through public API controller paths.
Exploit: (Educational Purposes!)
The vulnerability can be exploited by sending unauthenticated `GET` requests to specific API endpoints. An attacker with knowledge of a categoryId, faqId, or `tagId` can retrieve inactive FAQ content.
Direct Access: `GET /api/v3.1/faq/{categoryId}/{faqId}` – Returns the full and answer of the inactive FAQ.
Tag-Based Access: `GET /api/v3.1/faqs/tags/{tagId}` – Returns the and answer preview of inactive FAQs associated with the tag.
Tag-Based Access (v4): `GET /api/v4.0/faqs/tags/{tagId}` – Also returns the and answer preview, even when `api.onlyActiveFaqs=true` is set.
Protection:
The primary and most effective protection against this vulnerability is to upgrade to phpMyFAQ version 4.1.5 or later. This version implements a consistent public visibility check across all public FAQ API routes.
Impact:
Successful exploitation of this vulnerability leads to the unauthorized disclosure of inactive FAQ content. This content, intended to be non-public (e.g., drafts, review-only items), may contain sensitive information.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

