CVE-2024-54141 | phpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not available
Exp
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie postgreSQL) server's credential when connection to DB fails. This vulnerability is fixed in 4.0.0.
Conclusion & alert: CVE-2024-54141 is rated High Exploit Risk (62.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.48%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2024-54141
Exploit prediction scoring system (EPSS) score for CVE-2024-54141
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-vrjr-p3xp-xx2x · Severity: high · Ecosystem: composer — phpMyFAQ Generates an Error Message Containing Sensitive Information if database server is not available
Affected software / configurations for CVE-2024-54141