Security Features in phpMyAdmin - CVE-2015-7873

 

Security Features in phpMyAdmin - CVE-2015-7873

Published: October 28, 2015 / Updated: July 28, 2020


Vulnerability identifier: #VU32372
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-7873
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: phpMyAdmin
Affected software:
phpMyAdmin

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The redirection feature in url.php in phpMyAdmin 4.4.x before 4.4.15.1 and 4.5.x before 4.5.1 allows remote attackers to spoof content via the url parameter.


How to mitigate CVE-2015-7873

Install update from vendor's website.

Sources