High severity7.2NVD Advisory· Published Mar 25, 2024· Updated Jun 17, 2026
CVE-2024-28105
CVE-2024-28105
Description
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is vulnerable to manipulation of the Content-type and lang parameters, allowing attackers to upload malicious files with a .php extension, potentially leading to remote code execution (RCE) on the system. This vulnerability is fixed in 3.2.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
phpmyfaq/phpmyfaqPackagist | >= 3.2.5, < 3.2.6 | 3.2.6 |
Affected products
3- cpe:2.3:a:phpmyfaq:phpmyfaq:3.2.5:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/thorsten/phpMyFAQ/commit/9136883776af67dfdb0e8cf14f5e0ca22bf4f2e7nvdPatchWEB
- github.com/thorsten/phpMyFAQ/security/advisories/GHSA-pwh2-fpfr-x5gfnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-pwh2-fpfr-x5gfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-28105ghsaADVISORY
News mentions
0No linked articles in our index yet.