CVE-2022-23807Improper Authentication in Phpmyadmin

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 64.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 22
Latest updateJan 27

Description

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:5.1.3+dfsg1-1 (bookworm)
NVDphpmyadmin/phpmyadmin4.9.04.9.8+1
Packagistphpmyadmin/phpmyadmin4.9.04.9.8+1
Debianphpmyadmin/phpmyadmin< 4:5.1.3+dfsg1-1+2

Patches

🔴Vulnerability Details

4
GHSA
Improper Authentication in phpmyadmin2022-01-28
OSV
Improper Authentication in phpmyadmin2022-01-28
OSV
CVE-2022-23807: An issue was discovered in phpMyAdmin 42022-01-22
CVEList
CVE-2022-23807: An issue was discovered in phpMyAdmin 42022-01-22

📋Vendor Advisories

2
CISA ICS
Festo Didactic SE MES PC2026-01-27
Debian
CVE-2022-23807: phpmyadmin - An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A v...2022