CVE-2016-5731: XSS
Cross-site scripting (XSS) vulnerability in examples/openid.php in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to inject arbitrary web script or HTML via vectors involving an OpenID error message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5731?
The severity of CVE-2016-5731 is classified as medium due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-5731?
To fix CVE-2016-5731, upgrade to phpMyAdmin versions 4.0.10.16, 4.4.15.7, or 4.6.3 or later.
Which versions of phpMyAdmin are affected by CVE-2016-5731?
Affected versions include phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3.
What types of attacks can CVE-2016-5731 enable?
CVE-2016-5731 enables remote attackers to inject arbitrary web scripts or HTML via OpenID error message vectors.
Is CVE-2016-5731 still a concern for users of phpMyAdmin?
Yes, CVE-2016-5731 remains a concern for users of affected versions who have not applied the latest fixes.