phpMyFAQ
cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*
- <= 4.0.7
A vulnerability in phpMyFAQ versions 4.0-nightly-2025-10-03 and prior allows users to register multiple accounts using the same email address. This lack of email uniqueness can lead to account confusion and, in some cases, privilege escalation or account takeover, especially since email is commonly used for password resets and administrative notifications.
This vulnerability can cause a loss of accountability in user actions, as multiple accounts can be associated with a single email. It also creates ambiguity in password reset processes, allowing potential account takeover. Additionally, if one of the accounts with the duplicated email has administrative rights, it could lead to unauthorized privilege escalation.
To reproduce this vulnerability, register a user account with a specific email address. Then, register another account using the same email. Both accounts will be listed under the user management section in the admin panel.
Users can update to phpMyFAQ version 4.0.13, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.