Improper authorization control for web services In thorsten/phpmyfaq
Description
thorsten/phpmyfaq vulnerable to business logic errors thorsten/phpmyfaq prior to 3.1.12 allows users with edit-only permissions to add and delete categories and add FAQs. This has been fixed in 3.1.12.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.1.12 |
Aliases
1. 2. 3. 4.
References
1. 2.