CVE-2016-2039
phpmyadmin - security update
5.3
MEDIUM
CVSS 3.1
EPSS 0.38%
Description
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
How to fix CVE-2016-2039
To remediate CVE-2016-2039, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:4.5.4-1 or later
- —upgrade to 4:3.3.7-11 or later
Is CVE-2016-2039 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 4:4.5.4-1
- from 0, < 4:3.3.7-11
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |