CVE-2015-3903Phpmyadmin vulnerability

CWE-3107 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
1.2%
top 21.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 26
Latest updateMay 14

Description

libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.4.6.1-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:4.4.6.1-1+3
NVDphpmyadmin/phpmyadmin54 versions+53

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9qwv-267r-c7fq: libraries/Config2022-05-14
OSV
CVE-2015-3903: libraries/Config2015-05-26

📋Vendor Advisories

1
Debian
CVE-2015-3903: phpmyadmin - libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4....2015

💬Community

3
Bugzilla
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-7]2015-05-18
Bugzilla
CVE-2015-3903 phpMyAdmin4: phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub [epel-5]2015-05-18
Bugzilla
CVE-2015-3903 phpMyAdmin: Vulnerability allowing man-in-the-middle attack on API call to GitHub2015-05-14