CVE-2026-34728: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34728 is a path traversal vulnerability in phpMyFAQ's MediaBrowserController::index() method that enables arbitrary file deletion, compounded by a missing CSRF token check that allows unauthenticated exploitation via CSRF. It affects all phpMyFAQ versions up to and including 4.1.0 (Composer package phpmyfaq/phpmyfaq). The vulnerability was published by the maintainer on March 31, 2026, and patched in version 4.1.1 released the same day. It carries a CVSS v3.1 base score of 8.7 (High) per the GitHub Advisory, or 8.1 (High) per NVD scoring (Github Advisory, phpMyFAQ Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). In phpmyfaq/src/phpMyFAQ/Controller/Administration/Api/MediaBrowserController.php (lines 43–66), the fileRemove action reads a user-supplied name parameter, applies only FILTER_SANITIZE_SPECIAL_CHARS (which encodes HTML special characters but not ../ sequences), and directly concatenates it with the base upload path before calling unlink(). No basename() or realpath() check is performed to confirm the resolved path remains within the intended directory. Additionally, the endpoint is declared as an HTTP GET route but reads a JSON request body, bypassing typical same-origin CSRF protections for GET requests, and it omits the Token::verifyToken() call present in other controllers such as ImageController::upload() (Github Advisory, phpMyFAQ Advisory).

Impact

Successful exploitation allows deletion of arbitrary files accessible to the web server process, including critical application files such as content/core/config/database.php (causing total application failure due to database connection loss) and .htaccess or web.config files (disabling Apache/IIS security rules and exposing sensitive directories). Attackers can also delete log files to cover their tracks or remove security configuration files to weaken other protections. While confidentiality impact is rated None (no direct data exfiltration), the high integrity and availability impacts can result in complete service disruption and enable chained attacks (Github Advisory, phpMyFAQ Advisory).

Exploitability

A public proof-of-concept exploit is available in the official GitHub security advisory, including concrete curl commands and a JavaScript CSRF payload demonstrating deletion of database.php and .htaccess (phpMyFAQ Advisory). Direct exploitation requires an authenticated admin session, but the CSRF vector allows an unauthenticated attacker to trigger the deletion by tricking an authenticated admin into visiting a malicious page. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.09% (0.00169), indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing phpMyFAQ installations running version 4.1.0 or earlier using search engines (e.g., Shodan, Censys) or by checking the application's version disclosure on the login or admin page.
  2. Choose attack vector: Decide between direct exploitation (requires a valid admin session cookie) or CSRF-based exploitation (requires social engineering an authenticated admin).
  3. Direct exploitation — craft the request: With a valid PHPSESSID cookie for an admin account, send a GET request with a JSON body to the media browser API endpoint:
    curl -X GET 'https://target.example.com/admin/api/media-browser' \
      -H 'Content-Type: application/json' \
      -H 'Cookie: PHPSESSID=valid_admin_session' \
      -d '{"action":"fileRemove","name":"../../../content/core/config/database.php"}'
  4. CSRF exploitation — host a malicious page: If admin credentials are unavailable, host an HTML page containing the following JavaScript and trick an authenticated admin into visiting it:
    fetch('https://target.example.com/admin/api/media-browser', {
      method: 'GET',
      headers: {'Content-Type': 'application/json'},
      body: JSON.stringify({ action: 'fileRemove', name: '../../../content/core/config/database.php' }),
      credentials: 'include'
    });
  5. Achieve objective: The server deletes the targeted file (e.g., database.php), causing the application to lose its database connection and go offline, or deletes .htaccess to disable Apache security rules, enabling further attacks (phpMyFAQ Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET requests to /admin/api/media-browser containing a JSON body with "action":"fileRemove" and name values containing ../ sequences; cross-origin requests to this endpoint from unexpected referrer domains.
  • Logs: Web server access logs showing GET requests to the media browser API endpoint with oversized or JSON-formatted request bodies; application error logs indicating missing files (e.g., database.php, .htaccess) or failed unlink() calls outside the upload directory.
  • File System: Absence of content/core/config/database.php, .htaccess, web.config, or other critical configuration files that should be present; unexpected gaps in log files suggesting deletion to cover tracks.
  • Application Behavior: phpMyFAQ returning database connection errors or HTTP 500 responses site-wide following the deletion of database.php; Apache serving directory listings or bypassing security rules after .htaccess deletion (phpMyFAQ Advisory).

Mitigation and workarounds

Upgrade phpMyFAQ to version 4.1.1 or later, which was released on March 31, 2026, and addresses this vulnerability (phpMyFAQ Release). If immediate upgrade is not possible, apply the following mitigations: (1) add basename() and realpath() validation to restrict file deletion to the intended PMF_CONTENT_DIR/user/images/ directory; (2) enforce CSRF token validation via Token::verifyToken() on the endpoint; and (3) change the route's HTTP method from GET to POST or DELETE to align with proper HTTP semantics and restore standard CSRF protections. Web application firewall rules blocking requests to /admin/api/media-browser containing ../ in the request body can serve as an additional layer of defense (Github Advisory).

Community reactions

The vulnerability was reported by security researcher ik0z and disclosed through the phpMyFAQ GitHub security advisory program. Coverage appeared on The Hacker Wire, which published an article specifically on this CVE titled "phpMyFAQ Path Traversal + CSRF Leads to Arbitrary File Deletion" (The Hacker Wire). The issue was also tracked by VulDB and noted in the Red Hat CVE database, though Red Hat products are not directly affected. Community reaction has been moderate, with the dual nature of the vulnerability (path traversal combined with CSRF) drawing attention to the compounded risk of missing input validation and missing CSRF protection in the same endpoint.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management