Unlock of a Resource that is not Locked Affecting thorsten/phpmyfaq package, versions <4.1.4


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-THORSTENPHPMYFAQ-17660510
  • published27 Jun 2026
  • disclosed26 Jun 2026
  • creditSnailSploit

Introduced: 26 Jun 2026

NewCVE-2026-56396  (opens in a new tab)
CWE-832  (opens in a new tab)

How to fix?

Upgrade thorsten/phpmyfaq to version 4.1.4 or higher.

Overview

thorsten/phpmyfaq is a FAQ system for PHP and MySQL, PostgreSQL and other databases

Affected versions of this package are vulnerable to Unlock of a Resource that is not Locked in the editUser and updateUserRights processes. An attacker can gain unauthorized SuperAdmin privileges or grant arbitrary rights to any account by sending crafted requests to the affected API endpoints while authenticated as an administrator with the edit_user permission. This is only exploitable if the attacker holds the edit_user right but is not a SuperAdmin.

References

CVSS Base Scores

version 4.0
version 3.1