THREAT OPS › Threat News › [GHSA] GHSA-6pvm-2vjj-rx4w (medium) — phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
[GHSA] GHSA-6pvm-2vjj-rx4w (medium) — phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
GHSA-6pvm-2vjj-rx4w Severity: medium CVE: CVE-2026-47132
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
### Summary
An authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syn
Indicators of compromise
- c0b7158df4bfb11d57b1ef7d471760583c9c2faesha1
- CVE-2026-47132cve
Original source: https://github.com/advisories/GHSA-6pvm-2vjj-rx4w