VDB

CVE-2022-23807

CVE-2022-23807 PUBLISHED

An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.

EPSS 0.15% · 34.8th percentile

Risk Scores

EPSS Score
0.15%
34.8th percentile

Affected Products

VendorProductVersions
Bitnamiphpmyadmin4.9.0, 5.1.0
Bitnamiphpmyadmin5.1.0, 4.9.0

Timeline

  • Jan 22, 2022 CVE Published
  • Feb 8, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 24, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 7, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 21, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 5, 2023 EPSS Score
  • May 27, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›