Cross-site scripting in phpMyAdmin - CVE-2016-9857
Published: December 11, 2016 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected software
phpmyadmin (Alpine package)