{"id":"GHSA-5h62-f8fg-4w7q","summary":"Duplicate Advisory: phpMyFAQ: Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-7cx3-2qx2-3g6w. This link is maintained to preserve external references.\n\n### Original Description\nphpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpoint that allows any authenticated user to delete tags. Any logged-in user, including regular frontend users, can delete arbitrary tags by sending a DELETE request with a valid session cookie, resulting in permanent data loss and disruption of FAQ organization.","modified":"2026-09-10T03:50:45.848867553Z","published":"2026-05-15T21:31:32Z","withdrawn":"2026-06-09T00:05:36Z","database_specific":{"cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-21T21:17:33Z","nvd_published_at":"2026-05-15T19:17:03Z"},"references":[{"type":"WEB","url":"https://github.com/thorsten/phpMyFAQ/security/advisories/GHSA-7cx3-2qx2-3g6w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46365"},{"type":"PACKAGE","url":"https://github.com/thorsten/phpMyFAQ"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/phpmyfaq-missing-authorization-in-tag-deletion-endpoint"}],"affected":[{"package":{"name":"phpMyFAQ/phpMyFAQ","ecosystem":"Packagist","purl":"pkg:composer/phpMyFAQ/phpMyFAQ"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5h62-f8fg-4w7q/GHSA-5h62-f8fg-4w7q.json"}},{"package":{"name":"thorsten/phpMyFAQ","ecosystem":"Packagist","purl":"pkg:composer/thorsten/phpMyFAQ"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5h62-f8fg-4w7q/GHSA-5h62-f8fg-4w7q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"}]}