A vulnerability categorized as problematic has been discovered in thorsten phpMyFAQ up to 4.1.5. Affected by this vulnerability is an unknown functionality of the component Configuration API. Executing a manipulation of the argument upgrade.lastDownloadedPackage can lead to unrestricted upload.

This vulnerability is tracked as CVE-2026-66398. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.