Cross-site scripting in phpMyAdmin - CVE-2016-9857

 

Cross-site scripting in phpMyAdmin - CVE-2016-9857

Published: December 11, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33578
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2016-9857
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.


Affected software

phpMyAdmin
phpmyadmin (Alpine package)

How to mitigate CVE-2016-9857

Install update from vendor's website.

phpmyadmin (Alpine package) - update to 4.4.15.9-r0

External References

Related Security Bulletins