CVE-2015-6830
phpMyAdmin ReCaptcha bypass
EPSS 9.8%
描述
libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass a multiple-reCaptcha protection mechanism against brute-force credential guessing by providing a correct response to a single reCaptcha.
如何修補 CVE-2015-6830
要修補 CVE-2015-6830,請將受影響套件升級到下列已修補版本。
- Debian/phpmyadmin—升級至 4:4.4.14.1-1 或更新版本
- Packagist/phpmyadmin/phpmyadmin—升級至 4.3.13.2 或更新版本
CVE-2015-6830 正在被利用嗎?
中等 — EPSS 為 9.8%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 4:4.4.14.1-1
- >= 4.3.0, < 4.3.13.2