Back

HIGH

phpMyFAQ before 4.1.7 SQL Injection via Glossary

Published Aug 19, 2026

Description

phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 19, 2026

CISA Vulnrichment

Updated Aug 21, 2026

NVD

Status Analyzed
Modified Sep 1, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 21, 2026

GitHub

No data