FreeBSD : phpmyfaq -- multiple vulnerabilities (7a691536-968b-11f1-9863-50ebf6bdf8e9)

high Nessus Plugin ID 335134

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the 7a691536-968b-11f1-9863-50ebf6bdf8e9 advisory.

phpMyFAQ team reports:
The WebAuthn login flow never persists the challenge it issues, so the replay guard never runs. An attacker who captures a valid assertion can replay it to authenticate as the victim.
The brute-force throttle protecting the administration two-factor prompt is scoped to the session. An attacker who starts with a fresh cookie jar resets the counter and can guess TOTP codes without any effective rate limit.
An LDAP login silently reactivates a local account that an administrator has blocked, and the state change is not written to the audit log, so a revoked user regains access unnoticed.
The remember-me cookie is issued before the second factor has been verified. An attacker who knows only the password can keep the cookie from the incomplete login and use it to return as the fully authenticated user, bypassing two-factor authentication.
Glossary input is escaped before it is truncated. Truncation can cut an escape sequence in half, which allows an authenticated user to inject SQL into the resulting query.
A tracking file below the document root is served without authentication and contains password reset tokens, allowing an unauthenticated visitor to take over the accounts those tokens belong to.
The public PDF export does not check whether a FAQ record is active, so an unauthenticated visitor can retrieve the title and solution of drafts and unpublished entries.
Comment endpoints do not verify authorization for the parent FAQ record, exposing the comments, the personal data of the commenters, and attachment metadata of restricted records.
The PostgreSQL search backend declares the wrong LIKE ESCAPE character, which makes the wildcard-escaping fix ineffective on that backend.
The administration API endpoints that read the LDAP, Elasticsearch, OpenSearcr, and dashboard configuration only require a login instead of the CONFIGURATION_EDIT permission, so any authenticated user can read these settings.
An authenticated FAQ editor can reference a local file as an image in a FAQ entry and have the PDF export embed and disclose its contents.
The registration endpoints remain reachable even when security.enableRegistration is turned off, so visitors can still create accounts on an installation that is meant to be closed.
The content backup is written as a ZIP archive into the web-accessible document root, where anyone who guesses or learns its name can download the full contents of the installation.
The backup, database migration, and maintenance mode endpoints can be reached without authentication, allowing an unauthenticated attacker to export data or put the installation into maintenance mode.

Tenable has extracted the preceding description block directly from the FreeBSD security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://www.phpmyfaq.de/security/advisory-2026-08-04/

http://www.nessus.org/u?43cda5c9

Plugin Details

Severity: High

ID: 335134

File Name: freebsd_pkg_7a691536968b11f1986350ebf6bdf8e9.nasl

Version: 1.1

Type: Local

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/o:freebsd:freebsd, p-cpe:/a:freebsd:freebsd:phpmyfaq-php83, p-cpe:/a:freebsd:freebsd:phpmyfaq-php84, p-cpe:/a:freebsd:freebsd:phpmyfaq-php85

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Ease: No known exploits are available

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 8/4/2026