CVE-2021-4259CWE-597

phpRedisAdmin login.inc.php authHttpDigest wrong operator in string comparison

Medium · published December 19, 2022

CVSS v3.1
5.0
EPSS
1%
Percentile
53.5
In the wild
Unconfirmed
What it is

A vulnerability was found in phpRedisAdmin up to 1.16.1. It has been classified as problematic. This affects the function authHttpDigest of the file includes/login.inc.php. The manipulation of the argument response leads to use of wrong operator in string comparison. Upgrading to version 1.16.2 is able to address this issue. The name of the patch is 31aa7661e6db6f4dffbf9a635817832a0a11c7d9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216267.

The record
Technical detail
CVSS v3.1
5.0 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00776 · 53.5th percentile
Weakness
CWE-597 · Use of Wrong Operator in String Comparison
Published
2022-12-19T00:00Z
EPSS history
Timeline
  • 19 DEC 00:00Z
    phpRedisAdmin login.inc.php authHttpDigest wrong operator in string comparison
    cvelistv5