Lucene search

K
cvelistMitreCVELIST:CVE-2023-40619
HistorySep 20, 2023 - 12:00 a.m.

CVE-2023-40619

2023-09-2000:00:00
mitre
www.cve.org
3
cve-2023-40619
phppgadmin
untrusted data
deserialization
remote code execution

AI Score

10

Confidence

High

EPSS

0.002

Percentile

61.6%

phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP ‘unserialize()’ function in multiple places. An example is the functionality to manage tables in ‘tables.php’ where the ‘ma[]’ POST parameter is deserialized.

AI Score

10

Confidence

High

EPSS

0.002

Percentile

61.6%