PT-2022-2041 · Unknown+3 · Phpmyadmin+3

Rafael Pedrero

·

Published

2022-03-09

·

Updated

2024-06-15

·

CVE-2022-0813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PhpMyAdmin versions 5.1.1 and earlier PhpMyAdmin versions prior to 5.1.3
Description The issue allows an attacker to retrieve potentially sensitive information by creating invalid requests, affecting the lang parameter, the pma parameter, and the cookie section. This can enable a remote attacker to access confidential information.
Recommendations For PhpMyAdmin versions 5.1.1 and earlier, update to version 5.1.3 or later to resolve the issue. For PhpMyAdmin versions prior to 5.1.3, update to version 5.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the lang parameter, the pma parameter, and the cookie section to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1767
ALT-PU-2022-1787
ALT-PU-2023-7634
BDU:2022-01640
BIT-PHPMYADMIN-2022-0813
CVE-2022-0813
GHSA-VX8Q-J7H9-VF6Q
OPENSUSE-SU-2023:0047-1
OPENSUSE-SU-2024:12191-1

Affected Products

Alt Linux
Debian
Phpmyadmin
Red Os