Description
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 assigns values to arbitrary parameters referenced in the query string, which allows remote attackers to modify the SESSION superglobal array via a crafted request, related to a "remote variable manipulation vulnerability."
Remediation
References
Related Vulnerabilities
Python Improper Input Validation Vulnerability (CVE-2021-29921)
WordPress Plugin MetaSlider Information Disclosure (3.3.1)
WordPress Plugin Easy Testimonial Manager SQL Injection (1.2.0)
Python Improper Input Validation Vulnerability (CVE-2018-20852)
WordPress Plugin KJM Admin Notices Cross-Site Scripting (2.0.1)