CVE-2016-6616: SQL Injection
An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6616?
CVE-2016-6616 has been rated as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2016-6616?
To fix CVE-2016-6616, upgrade phpMyAdmin to version 4.6.4 or 4.4.15.8 or later.
Which versions of phpMyAdmin are affected by CVE-2016-6616?
CVE-2016-6616 affects all phpMyAdmin versions prior to 4.6.4 in the 4.6.x branch and prior to 4.4.15.8 in the 4.4.x branch.
What types of attacks can be executed using CVE-2016-6616?
CVE-2016-6616 allows attackers to conduct SQL injection attacks through the User group and Designer features.
Who is impacted by CVE-2016-6616?
Any user of the affected versions of phpMyAdmin who has access to the User group and Designer functionalities is at risk due to CVE-2016-6616.