THREAT OPS › Threat News › [GHSA] GHSA-pg62-f8g4-4wqh (high) — phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
[GHSA] GHSA-pg62-f8g4-4wqh (high) — phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
GHSA-pg62-f8g4-4wqh Severity: high CVE: None
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
## Overview
When phpMyFAQ hardened its admin permission-assignment endpoints against privilege escalation, it added a "a non-SuperAdmin may only assign rights they themselves hold" constraint to the user-rights endpoint (`UserContro
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-24421cve
Original source: https://github.com/advisories/GHSA-pg62-f8g4-4wqh