Announcement-ID: PMASA-2017-8

Date: 2017-03-28

Updated: 2018-05-01


Bypass $cfg['Servers'][$i]['AllowNoPassword']


A vulnerability was discovered where the restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false are bypassed under certain PHP versions. This can allow the login of users who have no password set even if the administrator has set $cfg['Servers'][$i]['AllowNoPassword'] to false (which is also the default).

This behavior depends on the PHP version used (it seems PHP 5 is affected, while PHP 7.0 is not).


We consider this vulnerability to be of moderate severity.

Mitigation factor

Set a password for all users.

Affected Versions

Version 4.0 prior to Version 4.4 (no longer supported) Version 4.6 (no longer supported) Version 4.7.0-beta1 and 4.7.0-rc1


Upgrade to phpMyAdmin, 4.7.0, or newer or apply patch listed below.


This weakness was discovered by phpMyAdmin team member Isaac Bennetch

Assigned CVE ids: CVE-2017-18264

CWE ids: CWE-661


The following commits have been made on the 4.0 branch to fix this issue:

The following commits have been made on the 4.7 branch to fix this issue:

More information

For further information and in case of questions, please contact the phpMyAdmin team. Our website is