An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
References
Link | Resource |
---|---|
https://www.phpmyadmin.net/security/PMASA-2022-1/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-01-21 18:15
Updated : 2022-01-27 06:24
NVD link : CVE-2022-23807
Mitre link : CVE-2022-23807
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
phpmyadmin
- phpmyadmin