
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69200 is an unauthenticated configuration backup download vulnerability in phpMyFAQ, an open-source FAQ web application. An unauthenticated remote attacker can trigger generation of a configuration backup ZIP via POST /api/setup/backup and subsequently download the archive from a web-accessible location, exposing sensitive files such as database.php containing database credentials. All versions prior to 4.0.16 are affected, including 4.1.0-alpha through 4.1.0-beta.2 and 4.1.0-RC. The vulnerability was disclosed on December 29, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Security Advisory).
The root cause is a missing authentication and authorization check on the /api/setup/backup API endpoint (CWE-202: Exposure of Sensitive Information Through Data Queries). The endpoint is exposed via a default .htaccess rewrite rule (RewriteRule ^api/setup/(check|backup|update-database) api/index.php) and the controller method SetupController.php → backup() contains no calls to hasValidToken(), userIsAuthenticated(), or any equivalent permission check. When the endpoint receives any non-empty POST body (interpreted as an installed version string), it invokes Update.php → createConfigBackup(), which writes a ZIP archive to content/core/config/ and returns a publicly accessible URL to the file. A public proof-of-concept is included in the official security advisory, requiring only two curl commands to trigger and retrieve the backup (Security Advisory, Patch Commit).
Successful exploitation results in full disclosure of sensitive configuration secrets — including database host, username, and password from database.php — to any unauthenticated network attacker. This information can be leveraged for follow-on attacks such as direct database compromise, unauthorized data exfiltration, or lateral movement within the hosting infrastructure. The attack requires no user interaction and is trivially executable with a single HTTP POST request, making the effective blast radius significant for any internet-exposed phpMyFAQ instance (GitHub Advisory).
A public proof-of-concept exploit is included in the official GitHub Security Advisory, demonstrating the full attack chain with two curl commands. The EPSS score is approximately 2.669% (86th percentile), indicating a meaningfully elevated exploitation probability relative to most CVEs (GitHub Advisory). A Nuclei detection template has also been added to the ProjectDiscovery nuclei-templates repository, further lowering the barrier for automated scanning. There is no confirmed evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).
/api/setup/backup endpoint with any non-empty body (e.g., a version string):curl -i -X POST "http://<TARGET>/api/setup/backup" \
-H "Content-Type: text/plain" \
--data "4.1.0-RC"backupFile field, which contains the direct URL to the generated ZIP archive under content/core/config/.curl -i "http://<TARGET>/content/core/config/phpmyfaq-config-backup.YYYY-MM-DD.zip" -o backup.zipdatabase.php to obtain database host, username, and password:unzip -p backup.zip database.php/api/setup/backup from external or unknown IP addresses; subsequent unauthenticated HTTP GET requests to paths matching content/core/config/phpmyfaq-config-backup.*.zip.POST /api/setup/backup returning HTTP 200 from unauthenticated sessions; follow-up GET requests to the backup ZIP URL from the same or different source IPs.content/core/config/ directory matching the pattern phpmyfaq-config-backup.YYYY-MM-DD.zip, especially if not created during a legitimate update process.Upgrade phpMyFAQ to version 4.0.16 or later, which removes the publicly accessible download link for the backup file and addresses the missing authentication on the backup endpoint (Patch Commit, GitHub Advisory). As an interim workaround, restrict network access to the /api/setup/backup endpoint via web server configuration (e.g., deny external access in .htaccess or via a WAF rule), and ensure the content/core/config/ directory is not web-accessible or that existing backup ZIPs are deleted. Audit the content/core/config/ directory for any previously generated backup archives and rotate any exposed database credentials immediately.
The vulnerability was reported by security researcher eclipse07077-ljw and published by the phpMyFAQ maintainer on December 29, 2025. The ProjectDiscovery team added a Nuclei detection template to their community templates repository, enabling automated scanning for vulnerable instances. Social media activity on Bluesky noted the availability of the Nuclei template, increasing awareness among the security community (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."