Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2023-40619
HistorySep 20, 2023 - 6:15 p.m.

CVE-2023-40619

2023-09-2018:15:12
Debian Security Bug Tracker
security-tracker.debian.org
30
phppgadmin
deserialization vulnerability
remote code execution
unserialize function
tables.php
untrusted data

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.6%

phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP ‘unserialize()’ function in multiple places. An example is the functionality to manage tables in ‘tables.php’ where the ‘ma[]’ POST parameter is deserialized.

OSVersionArchitecturePackageVersionFilename
Debian999allphppgadmin< 7.14.7+dfsg-1phppgadmin_7.14.7+dfsg-1_all.deb
Debian13allphppgadmin< 7.14.7+dfsg-1phppgadmin_7.14.7+dfsg-1_all.deb

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.6%