logo

Database

Sensitive information sent insecurely In phpmyadmin/phpmyadmin

Description

Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin PhpMyAdmin before 5.1.3 allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions