Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wf2-3ggj-78q9

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Improper Authentication in phpmyadmin

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.9.0, < 4.9.8

4.9.8

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 5.1.0, < 5.1.2

5.1.2

EPSS

Процентиль: 19%
0.00061
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
nvd
больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS3: 4.3
debian
больше 3 лет назад

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before ...

suse-cvrf
около 2 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 2 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 19%
0.00061
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-287