An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:4.9.5+dfsg1-2ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:5.1.1+dfsg1-5ubuntu1" } ] }
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:5.2.1+dfsg-3" } ] }
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:5.2.2-really+dfsg-2" } ] }
{ "binaries": [ { "binary_name": "phpmyadmin", "binary_version": "4:5.2.2-really5.2.2+20250121+dfsg-1" } ] }