CVE-2022-0813: PhpMyAdmin exposure of sensitive information
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pmaparameter, and the cookie section.
Other sources
PhpMyAdmin before 5.1.3 allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pmaparameter, and the cookie section.
— GitHub
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-0813.
What is the severity of CVE-2022-0813?
The severity of CVE-2022-0813 is high.
How does CVE-2022-0813 affect PhpMyAdmin?
CVE-2022-0813 allows an attacker to retrieve potentially sensitive information by creating invalid requests in PhpMyAdmin versions 5.1.1 and before.
Which sections of PhpMyAdmin are affected by CVE-2022-0813?
The lang parameter, the pma_parameter, and the cookie section of PhpMyAdmin are affected by CVE-2022-0813.
Are there any fixes or updates available for CVE-2022-0813?
Yes, updates for PhpMyAdmin versions 4.9.10 and 5.1.3 have been released to address CVE-2022-0813.