libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade phpmyadmin | Sep 20, 2017 | Sep 13, 2015 |
| Debian | — | Upgrade phpmyadmin | Nov 9, 2015 | Sep 13, 2015 |
| Freebsd | — | Upgrade phpMyAdmin | Dec 10, 2025 | Sep 8, 2015 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Sep 14, 2015 |
| Suse | — | Upgrade phpmyadmin | Dec 18, 2015 | Sep 13, 2015 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Sep 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub