PT-2022-11628 · Unknown · Phpredisadmin
Published
2022-12-19
·
Updated
2024-05-17
·
CVE-2021-4259
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpRedisAdmin versions up to 1.17.3
phpRedisAdmin versions up to 1.16.1 can be simplified to the above line as 1.17.3 includes all versions up to 1.16.1, so the final output is:
phpRedisAdmin versions up to 1.17.3
Description
A vulnerability was found in phpRedisAdmin. It has been classified as problematic. This affects the function
authHttpDigest of the file includes/login.inc.php. The manipulation of the argument response leads to use of wrong operator in string comparison.Recommendations
For phpRedisAdmin versions up to 1.17.3, upgrade to version 1.16.2 or later to address this issue.
As a temporary workaround, consider disabling the
authHttpDigest function until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpredisadmin