Cross-site request forgery In phpmyadmin
Description
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 4:4.5.4-1 | ||
debian 13 | 4:4.5.4-1 | ||
debian 11 | 4:4.5.4-1 | ||
debian 14 | 4:4.5.4-1 |
Aliases
1. 2. 3. 4. 5.