Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin
High severity
GitHub Reviewed
Published
Mar 11, 2022
to the GitHub Advisory Database
•
Updated Apr 22, 2024
Description
Published by the National Vulnerability Database
Mar 10, 2022
Published to the GitHub Advisory Database
Mar 11, 2022
Reviewed
Mar 14, 2022
Last updated
Apr 22, 2024
PhpMyAdmin before 5.1.3 allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
References