PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
{ "binaries": [ { "binary_version": "4:4.0.10-1ubuntu0.1+esm4", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.5.4.1-2ubuntu2.1+esm6", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.6.6-5ubuntu0.5+esm1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:4.9.5+dfsg1-2ubuntu0.1~esm1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.1.1+dfsg1-5ubuntu1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.1+dfsg-3", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.2-really5.2.2+20250121+dfsg-1", "binary_name": "phpmyadmin" } ] }