S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 10, 2026

CVE-2025-69200 Scanner

CVE-2025-69200 Scanner - Information Disclosure vulnerability in phpMyFAQ

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-69200
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can trigger generation of a configuration backup ZIP via `POST /api/setup/backup` and then download the generated ZIP from a web-accessible location. The ZIP contains sensitive configuration files (e.g., `database.php` with database credentials), leading to high-impact information disclosure and potential follow-on compromise. Version 4.0.16 fixes the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
phpMyFAQby thorsten
< 4.0.16
Updated Aug 22, 2026View on NVD →
Detail

phpMyFAQ is a widely used open-source FAQ software implemented in PHP. It is commonly used by organizations and communities to effectively manage and answer frequently asked questions. Users ranging from individual site owners to large enterprises install phpMyFAQ to improve customer support and knowledge management. This software allows for the creation, organization, and maintenance of a FAQ section on websites, reducing the workload on support teams. By providing self-serve information to users, phpMyFAQ streamlines customer service processes. The platform is designed to be extensible with plugins and can be integrated into existing web platforms.

The information disclosure vulnerability in phpMyFAQ is significant, allowing unauthenticated users to generate and download configuration backup ZIP files. This is primarily due to improper access controls that do not adequately restrict access to backup generation functions. Attackers leveraging this vulnerability can access sensitive configuration files stored in the system. Such files often contain sensitive data, including database credentials. This vulnerability has a wide impact range, affecting all users with potentially exposed systems. It requires immediate remediation to prevent unauthorized access and data breaches.

This vulnerability is located within the setup process of phpMyFAQ versions 4.0.16 and older. The vulnerable endpoint is accessed via a POST request to '/api/setup/backup', requiring no authentication. Attackers can exploit the endpoint to trigger the generation of a backup file in ZIP format. The vulnerability stems from a lack of proper authentication checks and improper handling of backup requests. The resulting backup file can thus be downloaded freely, enabling attackers to access its contents. Information within these files can be extracted due to JSON responses that include direct references to the backup file.

If exploited, the vulnerability can lead to severe security breaches. Attackers may gain unauthorized access to sensitive database credentials stored within the configuration files. This could allow them to manipulate the database, steal data, or escalate privileges within the application. They could potentially disrupt application functionality or exploit further vulnerabilities in the system. Ultimately, this may lead to data theft, loss of service, or misuse of application resources. Such compromises pose new risks, enabling attackers to perform subsequent unauthorized actions across interconnected systems.

REFERENCES

Solution Advice
  • Update phpMyFAQ to version 4.0.16 or later to patch the vulnerability.
  • Ensure proper authentication mechanisms are in place for accessing backup generation functionalities.
  • Review and audit configuration management practices to prevent unauthorized file access.
  • Conduct regular security assessments to identify and mitigate potential vulnerabilities in the system.
  • Educate and train staff on secure handling of sensitive configuration data to minimize risk.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.