highCVSS 7.5Vulnerability

GHSA-pm8c-3qq3-72w7

## Summary `CurrentUser::setTokenData()` in `phpmyfaq/src/phpMyFAQ/User/CurrentUser.php` at lines 515-534 builds a SQL UPDATE statement with `sprintf` and interpolates OAuth token fields (`refresh_token`, `access_token`, `code_verifier`, and `json_encode($token['jwt'])`) without calling `$db->escape()`. Sibling methods `setAuthSource()` and `setRememberMe()` in the same file do call `$db->escape()` on user-controlled values, so the omission is local to this method. An attacker (Bob) whose Azure AD display name contains a single quote (for example `O'Brien`, or a deliberate SQL payload) breaks out of the string literal and injects arbitrary SQL against the phpMyFAQ database. ## Details **Vulnerable code** (`phpmyfaq/src/phpMyFAQ/User/CurrentUser.php`, lines 513-534): ```php public function setTokenData(#[\SensitiveParameter] array $token): bool { $update = sprintf( " UPDATE %sfaquser SET refresh_token = '%s', access_token = '%s', code_verifier = '%s', jwt = '%s' WHERE user_id = %d", Database::getTablePrefix(), $token['refresh_token'], $token['access_token'], $token['code_verifier'], json_encode($token['jwt'], JSON_THROW_ON_ERROR), $this->getUserId(), ); return (bool) $this->configuration->getDb()->query($update); } ``` `json_encode()` does NOT escape single quotes. A JWT claim such as `{"preferred_username": "O'Malley"}` produces `{"preferred_username":"O'Malley"}` after `json_encode`, which terminates the SQL string literal at the apostrophe. **Correct pattern in the same file** (`setAuthSource`, line 458-461): ```php $update = sprintf( "UPDATE %sfaquser SET auth_source = '%s' WHERE user_id = %d", Database::getTablePrefix(), $this->configuration->getDb()->escape($authSource), $this->getUserId(), ); ``` `setRememberMe()` (line 471-478) follows the same safe pattern with `$db->escap

Properties

ghsa_id
GHSA-pm8c-3qq3-72w7
summary
phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
severity
high
cvss_score
7.5
cve_id
GHSA-pm8c-3qq3-72w7
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-05-06T20:44:39Z
source_url
https://github.com/advisories/GHSA-pm8c-3qq3-72w7
ghsa_updated
2026-05-06T20:44:39Z

Related Entities (6)

AFFECTS (2)

[Software]composer/thorsten/phpMyFAQ
[Software]composer/phpMyFAQ/phpMyFAQ

VULNERABLE_TO (2)

[Software]composer/phpMyFAQ/phpMyFAQ
[Software]composer/thorsten/phpMyFAQ

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph