phpMyAdmin Cryptographic Vulnerability
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Nov 7, 2023
Package
Affected versions
>= 4.0.0, < 4.0.10.13
>= 4.4.0, < 4.4.15.3
>= 4.5.0, < 4.5.4
Patched versions
4.0.10.13
4.4.15.3
4.5.4
Description
Published by the National Vulnerability Database
Feb 20, 2016
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jul 31, 2023
Last updated
Nov 7, 2023
The
suggestPassword
function injs/functions.js
in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on theMath.random
JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-force approach.References