THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pg62-f8g4-4wqh (high) — phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

[GHSA] GHSA-pg62-f8g4-4wqh (high) — phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

medgithub_advisoriesPublished 2026-08-25

GHSA-pg62-f8g4-4wqh Severity: high CVE: None

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

## Overview

When phpMyFAQ hardened its admin permission-assignment endpoints against privilege escalation, it added a "a non-SuperAdmin may only assign rights they themselves hold" constraint to the user-rights endpoint (`UserContro

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pg62-f8g4-4wqh