phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
http://techdefencelabs.com/security-advisories.html | third party advisory |
https://www.phpmyfaq.de/security/advisory-2014-09-16 | vendor advisory |