CVE-2022-23807

Name
CVE-2022-23807
Description
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.phpmyadmin.net/security/PMASA-2022-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* phpmyadmin >= 4.9.0 < 4.9.8
cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* phpmyadmin >= 5.1.0 < 5.1.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
phpmyadmin edge-community 5.1.2-r0 Andy Postnikov <apostnikov@gmail.com> fixed
phpmyadmin edge-community 4.9.2-r0 None possibly vulnerable
phpmyadmin edge-community 4.9.1-r0 None possibly vulnerable
phpmyadmin edge-community 4.9.0.1-r0 None possibly vulnerable
phpmyadmin 3.22-community 5.1.2-r0 None fixed
phpmyadmin 3.22-community 4.9.2-r0 None possibly vulnerable
phpmyadmin 3.22-community 4.9.1-r0 None possibly vulnerable
phpmyadmin 3.22-community 4.9.0.1-r0 None possibly vulnerable
phpmyadmin 3.21-community 5.1.2-r0 None fixed
phpmyadmin 3.20-community 5.1.2-r0 None fixed
phpmyadmin 3.19-community 5.1.2-r0 None fixed
phpmyadmin 3.18-community 5.1.2-r0 None fixed
phpmyadmin 3.17-community 5.1.2-r0 None fixed