GHSA-jvxx-8xxf-5495
Dashboard / Vulnerabilities / GHSA-jvxx-8xxf-5495
Summary: phpMyAdmin CSRF Vulnerability
Details: An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-9866, https://github.com/phpmyadmin/composer, https://security.gentoo.org/glsa/201701-32, https://web.archive.org/web/20210123194736/http://www.securityfocus.com/bid/94536, https://www.phpmyadmin.net/security/PMASA-2016-71
Affected packages
Package
Name: phpmyadmin/phpmyadmin
Purl: pkg:composer/phpmyadmin/phpmyadmin
Affected ranges
Type: ECOSYSTEM
Events:
