Duplicate Advisory: phpMyFAQ: Path traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins
High severity
GitHub Reviewed
Published
May 15, 2026
to the GitHub Advisory Database
•
Updated Jun 9, 2026
Withdrawn
This advisory was withdrawn on Jun 9, 2026
Description
Published by the National Vulnerability Database
May 15, 2026
Published to the GitHub Advisory Database
May 15, 2026
Reviewed
May 21, 2026
Withdrawn
Jun 9, 2026
Last updated
Jun 9, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-gh9p-q46p-57g2. This link is maintained to preserve external references.
Original Description
phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INSTANCE_DELETE permission to delete arbitrary directories. Attackers can submit traversal sequences like https://../../../ in the client URL parameter to recursively delete directories outside the intended clientFolder scope.
References