First published: Sat Jan 22 2022(Updated: )
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyAdmin phpMyAdmin | >=4.9.0<4.9.8 | |
phpMyAdmin phpMyAdmin | >=5.1.0<5.1.2 | |
composer/phpmyadmin/phpmyadmin | >=5.1.0<5.1.2 | 5.1.2 |
composer/phpmyadmin/phpmyadmin | >=4.9.0<4.9.8 | 4.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-23807.
The severity of CVE-2022-23807 is medium with a CVSS score of 4.3.
The affected software for CVE-2022-23807 is phpMyAdmin versions 4.9 before 4.9.8 and 5.1 before 5.1.2.
CVE-2022-23807 allows a valid user who is already authenticated to phpMyAdmin to bypass two-factor authentication for future login instances.
To fix CVE-2022-23807, it is recommended to upgrade to phpMyAdmin version 4.9.8 or 5.1.2.