GHSA-vqcm-r62w-w437

Suggest an improvement
Source
https://github.com/advisories/GHSA-vqcm-r62w-w437
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-vqcm-r62w-w437/GHSA-vqcm-r62w-w437.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-vqcm-r62w-w437
Aliases
Published
2022-05-14T02:55:16Z
Modified
2024-01-15T18:11:52.971638Z
Summary
phpMyAdmin remote variable manipulation
Details

libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."

Database specific
{
    "nvd_published_at": "2011-07-14T23:55:00Z",
    "cwe_ids": [
        "CWE-94"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-15T17:52:40Z"
}
References

Affected packages

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0
Fixed
3.3.10.2

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.4
Fixed
3.4.3.1