12 endpoints in ConfigurationTabController.php use userIsAuthenticated() (login-only check) instead of userHasPermission(PermissionType::CONFIGURATION_EDIT). This allows any authenticated user — including ones with zero admin permissions — to enumerate system configuration metadata including the permission model, active template, cache backend, mail provider, and translation provider.
The ConfigurationTabController contains 15 public endpoints. Three of them (list, save, uploadTheme) correctly enforce CONFIGURATION_EDIT permission:
// phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/ConfigurationTabController.php:63
public function list(Request $request): Response
{
$this->userHasPermission(PermissionType::CONFIGURATION_EDIT); // ✅ Correct
// ...
}
The remaining 12 only check that the user is logged in:
// phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/ConfigurationTabController.php:353
public function translations(): Response
{
$this->userIsAuthenticated(); // ❌ Missing permission check
// ...
}
The difference between these two methods is significant:
// AbstractController.php:258 — login-only
protected function userIsAuthenticated(): void
{
if (!$this->currentUser->isLoggedIn()) {
throw new UnauthorizedHttpException(challenge: 'User is not authenticated.');
}
}
// AbstractController.php:317 — login + permission check
protected function userHasPermission(PermissionType $permissionType): void
{
if (!$this->currentUser->isLoggedIn()) {
throw new UnauthorizedHttpException(challenge: 'User is not authenticated.');
}
$currentUser = $this->currentUser;
if (!$currentUser?->perm->hasPermission($currentUser->getUserId(), $permissionType->value)) {
throw new ForbiddenException(/* ... */);
}
}
There is no middleware or router-level authorization — the Kernel (Kernel.php) dispatches directly to controllers with only Language, Router, and Exception listeners. All authorization is at the controller method level.
The 12 affected endpoints (all GET, all under /admin/api/):
| # | Method | Route | Info Exposed |
|---|--------|-------|-------------|
| 1 | translations() | /configuration/translations | Available languages + current language |
| 2 | templates() | /configuration/templates | Available themes + active theme |
| 3 | faqsSortingKey() | /configuration/faqs-sorting-key/{current} | FAQ sorting key options |
| 4 | faqsSortingOrder() | /configuration/faqs-sorting-order/{current} | FAQ sorting order |
| 5 | faqsSortingPopular() | /configuration/faqs-sorting-popular/{current} | Popular FAQ sorting |
| 6 | permLevel() | /configuration/perm-level/{current} | Permission model (basic/medium) |
| 7 | releaseEnvironment() | /configuration/release-environment/{current} | Dev/production environment |
| 8 | searchRelevance() | /configuration/search-relevance/{current} | Search relevance config |
| 9 | seoMetaTags() | /configuration/seo-metatags/{current} | SEO meta tag config |
| 10 | translationProvider() | /configuration/translation-provider/{current} | Translation service (DeepL, etc.) |
| 11 | mailProvider() | /configuration/mail-provider/{current} | Mail provider (SMTP, etc.) |
| 12 | cacheAdapter() | /configuration/cache-adapter/{current} | Cache backend (filesystem/redis/memcached) |
The translations() and templates() endpoints directly read from config/filesystem and expose current settings. The {current} endpoints render HTML <option> dropdowns where the caller-supplied value gets the selected attribute — an attacker can enumerate possible values to discover the current configuration.
# Step 1: Authenticate as any user (even one with no admin permissions)
# and obtain the session cookie (pmf_auth_XXXX)
# Step 2: Query configuration endpoints that should require CONFIGURATION_EDIT permission
# Enumerate available languages and current language setting
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/translations
# Enumerate available templates and which is active
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/templates
# Discover permission model by trying known values
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/perm-level/basic
# Discover release environment
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/release-environment/development
# Discover cache backend
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/cache-adapter/filesystem
# Discover mail provider
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/mail-provider/smtp
# Discover translation provider
curl -s -b 'pmf_auth_XXXX=<session>' \
https://target.example/admin/api/configuration/translation-provider/deepl
Expected: HTTP 403 Forbidden for a user without configuration_edit permission.
Actual: HTTP 200 with configuration data in HTML option format.
Any authenticated user (e.g., a regular FAQ contributor or a user with minimal permissions) can enumerate:
While no credentials or secrets are directly exposed, this configuration metadata aids targeted follow-up attacks and violates the principle of least privilege — these endpoints exist to serve the admin configuration UI and should require the same CONFIGURATION_EDIT permission as the list and save endpoints.
Replace $this->userIsAuthenticated() with $this->userHasPermission(PermissionType::CONFIGURATION_EDIT) in all 12 affected methods:
// In ConfigurationTabController.php — apply to all 12 methods
// Before (line 355, and equivalent in all others):
$this->userIsAuthenticated();
// After:
$this->userHasPermission(PermissionType::CONFIGURATION_EDIT);
Affected methods: translations(), templates(), faqsSortingKey(), faqsSortingOrder(), faqsSortingPopular(), permLevel(), releaseEnvironment(), searchRelevance(), seoMetaTags(), translationProvider(), mailProvider(), cacheAdapter().
| Software | Affected versions |
|---|---|
thorsten / phpmyfaq
|
< 4.1.2 |
phpmyfaq / phpmyfaq
|
< 4.1.2 |
A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.
CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.
A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.
Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.
Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.
SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.