CVE-2016-5097
5.3
MEDIUM
CVSS 3.1
EPSS 0.55%
Description
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.
How to fix CVE-2016-5097
To remediate CVE-2016-5097, upgrade the affected package to a fixed version below.
- Debian/phpmyadmin—upgrade to 4:4.6.2-1 or later
Is CVE-2016-5097 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 4:4.6.2-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |