PhpMyAdmin before 5.1.3 allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
{
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-03-14T22:48:02Z",
"cwe_ids": [
"CWE-200"
],
"nvd_published_at": "2022-03-10T17:44:00Z"
}