phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 03 Oct 2025 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multiple distinct accounts to be created with the same email. Because email is often used as an identifier for password resets, notifications, and administrative actions, this flaw can cause account ambiguity and, in certain configurations, may lead to privilege escalation or account takeover. This issue is fixed in version 4.0.13. | |
Title | phpMyFAQ duplicate email registration allows multiple accounts with the same email | |
Weaknesses | CWE-284 CWE-286 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-03T20:45:27.185Z
Reserved: 2025-09-23T14:33:49.505Z
Link: CVE-2025-59943

Updated: 2025-10-03T20:24:03.619Z

Status : Received
Published: 2025-10-03T21:15:34.757
Modified: 2025-10-03T21:15:34.757
Link: CVE-2025-59943

No data.

No data.