CVE-2015-3902: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3902?
CVE-2015-3902 has a medium severity rating due to its potential impact on administrator session hijacking.
How do I fix CVE-2015-3902?
To resolve CVE-2015-3902, upgrade phpMyAdmin to version 4.0.10.10 or later, 4.2.13.3 or later, 4.3.13.1 or later, or 4.4.6.1 or later.
Which versions of phpMyAdmin are affected by CVE-2015-3902?
CVE-2015-3902 affects phpMyAdmin versions before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1.
What type of vulnerability is CVE-2015-3902?
CVE-2015-3902 is a cross-site request forgery (CSRF) vulnerability allowing attackers to hijack administrator sessions.
Who can be impacted by CVE-2015-3902?
CVE-2015-3902 can significantly impact users with administrator privileges in phpMyAdmin, as it allows unauthorized configuration changes.