CVE-2016-9866: CSRF
An issue was discovered in phpMyAdmin. When the argseparator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9866?
CVE-2016-9866 is known to have a medium severity rating due to the potential for Cross-Site Request Forgery (CSRF) exploitation.
How do I fix CVE-2016-9866?
To fix CVE-2016-9866, you should upgrade phpMyAdmin to version 4.6.5, 4.4.15.9, or newer to patch the vulnerability.
What is the impact of CVE-2016-9866?
The impact of CVE-2016-9866 allows an attacker to perform unauthorized actions on behalf of users, exploiting the CSRF vulnerability.
Which versions of phpMyAdmin are affected by CVE-2016-9866?
CVE-2016-9866 affects phpMyAdmin versions prior to 4.6.5, 4.4.15.9, and all versions of 4.0.x.
Is there a workaround for CVE-2016-9866?
There are no official workarounds for CVE-2016-9866; upgrading to the latest versions is the recommended action.