Description
phpMyFAQ through 4.1.10 contains a missing authorization vulnerability in the MCP server faq_search tool that allows MCP clients to read restricted FAQs because Search::searchDatabase() never applies user or group permission checks. Attackers connected to the phpmyfaq:mcp:server can issue search queries to retrieve the full question and answer text of active FAQs restricted to specific users or groups.
Related CPE's
Could not find any relations
References
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
3.3 · Low
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-11T14:17:04.667Z
2 hours agoLast modified
2026-10-11T14:17:04.777Z
2 hours ago