An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
{ "binaries": [ { "binary_version": "4:4.9.5+dfsg1-2ubuntu0.1~esm1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.1.1+dfsg1-5ubuntu1", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.1+dfsg-3", "binary_name": "phpmyadmin" } ] }
{ "binaries": [ { "binary_version": "4:5.2.2-really5.2.2+20250121+dfsg-1", "binary_name": "phpmyadmin" } ] }