CVE-2023-40619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
20/09/2023
Last modified:
03/11/2023

Description

phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phppgadmin_project:phppgadmin:*:*:*:*:*:*:*:* 7.14.4 (including)