CVE-2024-54141

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's credential when connection to DB fails. This vulnerability is fixed in 4.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmyfaq:phpmyfaq:4.0.0:alpha:*:*:*:*:*:*

History

15 Aug 2025, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:phpmyfaq:phpmyfaq:4.0.0:alpha:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-209
First Time Phpmyfaq
Phpmyfaq phpmyfaq
References () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-vrjr-p3xp-xx2x - () https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-vrjr-p3xp-xx2x - Exploit, Vendor Advisory
References () https://github.com/thorsten/phpMyFAQ/commit/b9289a0b2233df864361c131cd177b6715fbb0fe - () https://github.com/thorsten/phpMyFAQ/commit/b9289a0b2233df864361c131cd177b6715fbb0fe - Patch

06 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 15:15

Updated : 2025-08-15 18:44


NVD link : CVE-2024-54141

Mitre link : CVE-2024-54141


JSON object : View

Products Affected

phpmyfaq

  • phpmyfaq
CWE

No CWE.