PMASA-2016-57
Announcement-ID: PMASA-2016-57
Date: 2016-11-25
Summary
Open redirection
Description
A vulnerability was discovered where a user can be tricked in to following a link leading to phpMyAdmin, which after authentication redirects to another malicious site.
The attacker must sniff the user's valid phpMyAdmin token.
Severity
We consider this vulnerability to be of moderate severity.
Affected Versions
All 4.0.x versions (prior to 4.0.10.16) are affected
Solution
Upgrade to phpMyAdmin 4.0.10.16, or newer or apply patch listed below.
References
Assigned CVE IDs: CVE-2016-4412
CWE IDs: CWE-661
Patches
The following commits have been made on the 4.0 branch to fix this issue:
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.