CVE-2014-6047

Severity CVSS v4.0:
Pending analysis
Type:
CWE-275 Permission Issues
Publication date:
28/08/2018
Last modified:
23/10/2018

Description

phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpmyfaq:phpmyfaq:*:*:*:*:*:*:*:* 2.8.13 (excluding)