CVE-2015-3903: Medium severity phpmyadmin vulnerability
libraries/Config.class.php in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 disables X.509 certificate verification for GitHub API calls over SSL, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3903?
CVE-2015-3903 has a medium severity rating, as it allows man-in-the-middle attacks that can expose sensitive information.
How do I fix CVE-2015-3903?
To fix CVE-2015-3903, upgrade phpMyAdmin to version 4.0.10.10, 4.2.13.3, 4.3.13.1, or 4.4.6.1 or later.
What versions of phpMyAdmin are affected by CVE-2015-3903?
CVE-2015-3903 affects phpMyAdmin versions 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1.
What type of vulnerability is CVE-2015-3903?
CVE-2015-3903 is a vulnerability that disables X.509 certificate verification for GitHub API calls over SSL.
Can CVE-2015-3903 lead to data compromise?
Yes, CVE-2015-3903 can lead to data compromise through man-in-the-middle attacks, potentially allowing attackers to spoof servers.