CVE-2022-23807: Medium severity phpmyadmin vulnerability
Published Jan 22, 2022
·Updated
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
Affected Software
4 affected componentsFixes available
composer/phpmyadmin/phpmyadmin>=5.1.0<5.1.2
5.1.2
composer/phpmyadmin/phpmyadmin>=4.9.0<4.9.8
4.9.8
phpMyAdmin phpMyAdmin>=4.9.0<4.9.8
phpMyAdmin phpMyAdmin>=5.1.0<5.1.2
Remediation
Patch Available
Event History
Jan 22, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 28, 2022
Advisory Published
via GitHub·10:44 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-23807.
2
What is the severity of CVE-2022-23807?
The severity of CVE-2022-23807 is medium with a CVSS score of 4.3.
3
What is the affected software for CVE-2022-23807?
The affected software for CVE-2022-23807 is phpMyAdmin versions 4.9 before 4.9.8 and 5.1 before 5.1.2.
4
How does CVE-2022-23807 impact users?
CVE-2022-23807 allows a valid user who is already authenticated to phpMyAdmin to bypass two-factor authentication for future login instances.
5
How can I fix CVE-2022-23807?
To fix CVE-2022-23807, it is recommended to upgrade to phpMyAdmin version 4.9.8 or 5.1.2.