Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc8v-m2rw-4fc4

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

EPSS

Процентиль: 59%
0.00382
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
nvd
почти 10 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

CVSS3: 5.3
debian
почти 10 лет назад

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x ...

suse-cvrf
почти 10 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 59%
0.00382
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200