CVE-2016-9857: XSS
An issue was discovered in phpMyAdmin. XSS is possible because of a weakness in a regular expression used in some JavaScript processing. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What versions are affected by CVE-2016-9857?
CVE-2016-9857 affects phpMyAdmin versions 4.0.x prior to 4.0.10.18, 4.4.x prior to 4.4.15.9, and 4.6.x prior to 4.6.5.
What is the severity of CVE-2016-9857?
CVE-2016-9857 is classified as a cross-site scripting (XSS) vulnerability.
How do I fix CVE-2016-9857?
To mitigate CVE-2016-9857, upgrade your phpMyAdmin installation to version 4.6.5 or later, 4.4.15.9 or later, or 4.0.10.18 or later.
What type of vulnerability is CVE-2016-9857?
CVE-2016-9857 is a cross-site scripting (XSS) vulnerability caused by a weakness in regular expressions used in JavaScript processing.
Can CVE-2016-9857 be exploited remotely?
Yes, CVE-2016-9857 can potentially be exploited remotely by an attacker to execute scripts in the context of the user's browser.