Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08180
HistoryJan 25, 2022 - 12:00 a.m.

phpMyAdmin authorization problem vulnerability

2022-01-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
phpmyadmin
mysql
database management
security vulnerability
two-factor authentication

EPSS

0.001

Percentile

22.7%

phpMyAdmin is a free, web-based MySQL database management tool from the Phpmyadmin team. The tool is capable of creating and deleting databases, creating, deleting, and modifying database tables, executing SQL script commands, and more. phpMyAdmin suffers from a security vulnerability that stems from the fact that valid authenticated users can manipulate other accounts to bypass two-factor authentication for future login instances. No details of the vulnerability are currently available.