CVE-2016-6615: XSS
XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6615?
CVE-2016-6615 has been rated as a high severity vulnerability due to its potential to enable Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2016-6615?
To fix CVE-2016-6615, it is recommended to upgrade phpMyAdmin to a version that has addressed this vulnerability.
Which versions of phpMyAdmin are affected by CVE-2016-6615?
CVE-2016-6615 affects phpMyAdmin versions from 4.4.0 to 4.6.3.
What types of XSS issues are associated with CVE-2016-6615?
CVE-2016-6615 involves XSS issues triggered by specially-crafted database names and queries within the phpMyAdmin interface.
Are there any workarounds for CVE-2016-6615?
While the best course of action is to upgrade to a patched version, limiting access to phpMyAdmin can mitigate the risk of CVE-2016-6615.