Lucene search

K
osvGoogleOSV:GHSA-X962-W72P-MV7Q
HistoryMay 17, 2022 - 5:07 a.m.

phpMyAdmin Global variables scope injection vulnerability

2022-05-1705:07:49
Google
osv.dev
4
phpmyadmin
injection vulnerability
import.php
globals superglobal array
configuration
crafted request
software

EPSS

0.001

Percentile

50.9%

import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.