{"id":"CVE-2013-4729","aliases":["GHSA-x962-w72p-mv7q"],"url":"https://o3.security/vulnerability/CVE-2013-4729","summary":"phpMyAdmin Global variables scope injection vulnerability","details":"import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authenticated users to modify the GLOBALS superglobal array, and consequently change the configuration, via a crafted request.","published":"2013-07-04T14:33:41Z","modified":"2026-04-10T03:43:02.135265Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"phpmyadmin/phpmyadmin","fixedVersion":"4.0.4.1"}],"fix":{"url":"https://github.com/phpmyadmin/phpmyadmin/commit/012464268420e53a9cd81cbb4a43988d70393c36","label":"phpmyadmin/phpmyadmin@0124642"},"references":[{"type":"ADVISORY","url":"http://www.phpmyadmin.net/home_page/security/PMASA-2013-7.php"},{"type":"EVIDENCE","url":"https://github.com/phpmyadmin/phpmyadmin/commit/012464268420e53a9cd81cbb4a43988d70393c36"},{"type":"FIX","url":"https://github.com/phpmyadmin/phpmyadmin/commit/012464268420e53a9cd81cbb4a43988d70393c36"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:02.135265Z"}}