An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
References
Link | Resource |
---|---|
https://security.gentoo.org/glsa/202311-17 | |
https://www.phpmyadmin.net/security/PMASA-2022-1/ | Patch Vendor Advisory |
https://security.gentoo.org/glsa/202311-17 | |
https://www.phpmyadmin.net/security/PMASA-2022-1/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.gentoo.org/glsa/202311-17 - | |
References | () https://www.phpmyadmin.net/security/PMASA-2022-1/ - Patch, Vendor Advisory |
26 Nov 2023, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2022-01-22 02:15
Updated : 2024-11-21 06:49
NVD link : CVE-2022-23807
Mitre link : CVE-2022-23807
CVE.ORG link : CVE-2022-23807
JSON object : View
Products Affected
phpmyadmin
- phpmyadmin
CWE
CWE-287
Improper Authentication