Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r326-mp8g-6xfc

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

phpMyAdmin Bypass white-list protection for URL redirection

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.6, < 4.6.5

4.6.5

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.4, < 4.4.15.9

4.4.15.9

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 4.0, < 4.0.10.18

4.0.10.18

EPSS

Процентиль: 51%
0.00279
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
nvd
больше 8 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

CVSS3: 7.5
debian
больше 8 лет назад

An issue was discovered in phpMyAdmin. Due to the limitation in URL ma ...

EPSS

Процентиль: 51%
0.00279
Низкий

7.5 High

CVSS3