PT-2022-16279 · Unknown+2 · Phpmyadmin+2

Dipak Panchal

+1

·

Published

2020-01-16

·

Updated

2024-06-15

·

CVE-2022-23808

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions 5.1 through 5.1.1 phpMyAdmin version 5.1.2 is not affected, but all versions prior to 5.1.2 are vulnerable.
Description An issue was discovered in phpMyAdmin, allowing an attacker to inject malicious code into aspects of the setup script, which can enable XSS or HTML injection. This can potentially allow attackers to manipulate user accounts or bypass two-factor authentication in subsequent authentication sessions. Additionally, weaknesses were identified that allow malicious users to submit malicious information, presenting XSS or HTML injection attacks in the graphical setup page. In some scenarios, sensitive information such as database names can be part of the URL, and error messages during failed logon attempts can reveal the target database server's hostname or IP address.
Recommendations For phpMyAdmin versions 5.1 through 5.1.1, update to version 5.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the setup script until a patch is available. Avoid using the graphical setup page with untrusted input until the issue is resolved. Enable the cookie parameter "SameSite" when using PHP version 7.3 or newer to enhance security.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1061
ALT-PU-2022-1767
ALT-PU-2022-1787
ALT-PU-2023-1174
ALT-PU-2023-1505
ALT-PU-2023-1600
ALT-PU-2023-7634
BIT-PHPMYADMIN-2022-23808
CVE-2022-23808
GHSA-VCWC-6MR9-8M7C
MGASA-2022-0036
OPENSUSE-SU-2023:0047-1
OPENSUSE-SU-2024:11765-1

Affected Products

Alt Linux
Debian
Phpmyadmin