CVE-2016-9856: XSS
An XSS issue was discovered in phpMyAdmin because of an improper fix for CVE-2016-2559 in PMASA-2016-10. This issue is resolved by using a copy of a hash to avoid a race condition. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9856?
CVE-2016-9856 has a medium severity, as it allows for cross-site scripting (XSS) attacks in vulnerable versions of phpMyAdmin.
How do I fix CVE-2016-9856?
To fix CVE-2016-9856, upgrade to phpMyAdmin version 4.6.5 or later, 4.4.15.9 or later, or 4.0.10.18 or later.
Which versions of phpMyAdmin are affected by CVE-2016-9856?
Versions 4.6.x prior to 4.6.5, 4.4.x prior to 4.4.15.9, and 4.0.x prior to 4.0.10.18 are all affected by CVE-2016-9856.
What type of vulnerability is CVE-2016-9856?
CVE-2016-9856 is a cross-site scripting (XSS) vulnerability due to improper validation in phpMyAdmin.
When was CVE-2016-9856 discovered?
CVE-2016-9856 was discovered in 2016 as an issue related to a previous fix for another vulnerability.