CVE-2025-69200
phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains sensitive configuration files (e.g., `database.php` with database credentials), leading to high-impact information disclosure and potential follow-on compromise. Version 4.0.16 fixes the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 2.19%
- CWE
- CWE-202
- Published
- 2025-12-29
- Last modified
- 2026-03-13
Affected products
- thorsten phpMyFAQ
Weakness type
Related vulnerabilities
- CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability...
- CVE-2026-25703 — Potential information leakage from manager /network/graph API in NeuVector
- CVE-2026-70473 — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
- CVE-2026-42797 — Apache Syncope: JexlContextBuilder Information Disclosure
- CVE-2026-40245 — Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
- CVE-2026-30778 — Apache SkyWalking: The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.
- CVE-2026-33530 — InvenTree Vulnerable to ORM Filter Injection
- CVE-2026-3546 — e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action