Lucene search

K
osvGoogleOSV:CVE-2022-23807
HistoryJan 22, 2022 - 2:15 a.m.

CVE-2022-23807

2022-01-2202:15:07
Google
osv.dev
10
phpmyadmin
authentication
bypass

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

22.7%

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.