CVE Vulnerabilities

CVE-2022-23807

Improper Authentication

Published: Jan 22, 2022 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
PhpmyadminPhpmyadmin4.9.0 (including)4.9.8 (excluding)
PhpmyadminPhpmyadmin5.1.0 (including)5.1.2 (excluding)
PhpmyadminUbuntuesm-apps/focal*
PhpmyadminUbuntufocal*
PhpmyadminUbuntuimpish*
PhpmyadminUbuntukinetic*
PhpmyadminUbuntulunar*
PhpmyadminUbuntumantic*
PhpmyadminUbuntuoracular*
PhpmyadminUbuntuplucky*
PhpmyadminUbuntutrusty*
PhpmyadminUbuntuxenial*

Potential Mitigations

References