CVE-2015-6830: Infoleak
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6830?
CVE-2015-6830 is classified as a medium severity vulnerability that allows bypassing of reCaptcha protections.
How do I fix CVE-2015-6830?
To fix CVE-2015-6830, upgrade phpMyAdmin to version 4.3.13.2, 4.4.14.1, or later.
What versions of phpMyAdmin are affected by CVE-2015-6830?
CVE-2015-6830 affects phpMyAdmin versions 4.3.0 through 4.3.13.1 and 4.4.0 through 4.4.13.
What type of attacks can CVE-2015-6830 enable?
CVE-2015-6830 can enable remote attackers to perform brute-force credential guessing by bypassing multiple reCaptcha checks.
Is there a patch available for CVE-2015-6830?
Yes, a patch is included in the updated versions of phpMyAdmin released after the vulnerability was discovered.