ALT-PU-2023-7634-3
Package phpMyAdmin updated to version 5.2.1-alt1 for branch c9f2 in task 335214.
Closed vulnerabilities
BDU:2022-01640
Уязвимость веб-интерфейса веб-приложения для администрирования cистем управления базами данных phpMyAdmin, позволяющая нарушителю получить доступ к конфиденциальной информации
BDU:2023-07577
Уязвимость веб-приложения для администрирования cистем управления базами данных phpMyAdmin, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
Modified: 2025-04-01
CVE-2020-22452
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
- http://phpmyadmin.com
- http://phpmyadmin.com
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/blob/master/ChangeLog
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/issues/15898
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
- https://github.com/phpmyadmin/phpmyadmin/pull/16004
Modified: 2024-11-21
CVE-2022-0813
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
- GLSA-202311-17
- GLSA-202311-17
- https://www.incibe-cert.es/en/early-warning/security-advisories/phpmyadmin-exposure-sensitive-information
- https://www.incibe-cert.es/en/early-warning/security-advisories/phpmyadmin-exposure-sensitive-information
- https://www.phpmyadmin.net/news/2022/2/11/phpmyadmin-4910-and-513-are-released/
- https://www.phpmyadmin.net/news/2022/2/11/phpmyadmin-4910-and-513-are-released/
Modified: 2024-11-21
CVE-2022-23807
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
Modified: 2024-11-21
CVE-2022-23808
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
Modified: 2025-03-21
CVE-2023-25727
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.