The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 2.11.11.3, and 3.3.x before 3.3.9.2, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpmyadmin | Jul 30, 2024 | Feb 14, 2011 |
| Gentoo Linux | — | Upgrade dev-db/phpmyadmin. | Oct 30, 2017 | Feb 14, 2011 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 2, 2017 | Feb 14, 2011 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Feb 14, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub