PT-2022-16278 · Unknown+2 · Phpmyadmin+2

William Desportes

·

Published

2020-01-16

·

Updated

2024-06-15

·

CVE-2022-23807

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 4.9 through 4.9.7 phpMyAdmin versions 5.1 through 5.1.1
Description A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances. This issue is related to how phpMyAdmin processes two-factor authentication.
Recommendations For phpMyAdmin versions 4.9 through 4.9.7, update to version 4.9.8 or later to resolve the issue. For phpMyAdmin versions 5.1 through 5.1.1, update to version 5.1.2 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1061
ALT-PU-2022-1767
ALT-PU-2022-1787
ALT-PU-2023-7634
BIT-PHPMYADMIN-2022-23807
CVE-2022-23807
GHSA-8WF2-3GGJ-78Q9
MGASA-2022-0036
OPENSUSE-SU-2023:0047-1
OPENSUSE-SU-2023:0154-1
OPENSUSE-SU-2024:11765-1

Affected Products

Alt Linux
Debian
Phpmyadmin