|Date: (C)2011-02-14 (M)2017-08-18|
|CVSS Score: 6.5||Access Vector: NETWORK|
|Exploitability Subscore: 8.0||Access Complexity: LOW|
|Impact Subscore: 6.4||Authentication: SINGLE_INSTANCE|
| ||Confidentiality: PARTIAL|
| ||Integrity: PARTIAL|
| ||Availability: PARTIAL|
The PMA_Bookmark_get function in libraries/bookmark.lib.php in phpMyAdmin 2.11.x before 126.96.36.199, and 3.3.x before 188.8.131.52, does not properly restrict bookmark queries, which makes it easier for remote authenticated users to trigger another user's execution of a SQL query by creating a bookmark.