⚠ Withdrawn by GitHub Security Advisories

Withdrawn: June 8, 2026

GHSA-ch9q-c9mp-j5gqCriticalCVSS 9.8Disclosed before NVD

Duplicate Advisory: phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha

Published
May 15, 2026
Last Modified
June 8, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-289f-fq7w-6q2w. This link is maintained to preserve external references.

Original Description

phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and BuiltinCaptcha::saveCaptcha() methods that interpolate unsanitized User-Agent headers into DELETE and INSERT queries. Unauthenticated attackers can exploit the public GET /api/captcha endpoint by crafting malicious User-Agent headers to perform time-based blind SQL injection, extracting sensitive data including user credentials, admin tokens, and SMTP credentials from the database.

🎯 Affected products2

  • composer/thorsten/phpmyfaq:< 4.1.2
  • composer/phpmyfaq/phpmyfaq:< 4.1.2

🔗 References (5)