QID 730339

Date Published: 2022-02-07

QID 730339: PhpMyAdmin Authentication Bypass Vulnerability (PMASA-2022-1)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2022-23807: A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

Affected Versions:
phpMyAdmin versions from 4.9.x prior to 4.9.8.
phpMyAdmin versions from 5.1.x prior to 5.1.2.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation of this vulnerability may allow an authenticated user to manipulate and bypass two-factor authentication for future login instances.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 4.9.8 or 5.1.2 or the latest version.
    Vendor References

    CVEs related to QID 730339

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2022-1 URL Logo www.phpmyadmin.net/security/PMASA-2022-1/