Security Advisory

CVE-2026-76205

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 14:01:53
Last updated 2026-08-21 19:21:08
Assigner VulnCheck
CVSS score 8.6
State PUBLISHED

Description

phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in a SQL literal. Authenticated users with glossary add or edit permissions can craft a payload with a dangling backslash to escape the closing quote and inject arbitrary SQL commands to read sensitive database information.