First published: Sat Feb 20 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the normalization page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =22 | |
Fedora | =23 | |
SUSE Linux | =42.1 | |
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 | |
phpMyAdmin | =4.4.1 | |
phpMyAdmin | =4.4.1.1 | |
phpMyAdmin | =4.4.2 | |
phpMyAdmin | =4.4.3 | |
phpMyAdmin | =4.4.4 | |
phpMyAdmin | =4.4.5 | |
phpMyAdmin | =4.4.6 | |
phpMyAdmin | =4.4.6.1 | |
phpMyAdmin | =4.4.7 | |
phpMyAdmin | =4.4.8 | |
phpMyAdmin | =4.4.9 | |
phpMyAdmin | =4.4.10 | |
phpMyAdmin | =4.4.11 | |
phpMyAdmin | =4.4.12 | |
phpMyAdmin | =4.4.13 | |
phpMyAdmin | =4.4.13.1 | |
phpMyAdmin | =4.4.14.1 | |
phpMyAdmin | =4.4.15 | |
phpMyAdmin | =4.4.15.1 | |
phpMyAdmin | =4.4.15.2 | |
phpMyAdmin | =4.4.15.3 | |
phpMyAdmin | =4.5.0 | |
phpMyAdmin | =4.5.0.1 | |
phpMyAdmin | =4.5.0.2 | |
phpMyAdmin | =4.5.1 | |
phpMyAdmin | =4.5.2 | |
phpMyAdmin | =4.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-2043 is considered moderate due to the potential for remote authenticated users to exploit the XSS vulnerability.
To fix CVE-2016-2043, update phpMyAdmin to version 4.4.15.3 or 4.5.4 or later.
CVE-2016-2043 affects phpMyAdmin versions 4.4.x prior to 4.4.15.3 and 4.5.x prior to 4.5.4, along with specific versions of Fedora and openSUSE.
CVE-2016-2043 is a Cross-site Scripting (XSS) vulnerability that allows remote authenticated users to inject arbitrary web script or HTML.
No, CVE-2016-2043 requires remote authenticated users to execute the exploit.