First published: Wed Mar 09 2022(Updated: )
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | <=5.1.1 | |
composer/phpmyadmin/phpmyadmin | <5.1.3 | 5.1.3 |
This vulnerability has been solved by the phpMyAdmin team in the 5.1.3 version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-0813.
The severity of CVE-2022-0813 is high.
CVE-2022-0813 allows an attacker to retrieve potentially sensitive information by creating invalid requests in PhpMyAdmin versions 5.1.1 and before.
The lang parameter, the pma_parameter, and the cookie section of PhpMyAdmin are affected by CVE-2022-0813.
Yes, updates for PhpMyAdmin versions 4.9.10 and 5.1.3 have been released to address CVE-2022-0813.