PMASA-2016-3
Announcement-ID: PMASA-2016-3
Date: 2016-01-24
Summary
Multiple XSS vulnerabilities.
Description
- With a crafted table name it is possible to trigger an XSS attack in the database search page.
- With a crafted SET value or a crafted search query, it is possible to trigger an XSS attacks in the zoom search page.
- With a crafted hostname header, it is possible to trigger an XSS attacks in the home page.
Severity
We consider these vulnerabilities to be non-critical.
Mitigation factor
These vulnerabilities can be triggered only by someone who is logged in to phpMyAdmin, as the usual token protection prevents non-logged-in users from accessing the required pages.
Affected Versions
Versions 4.0.x (prior to 4.0.10.13), 4.4.x (prior to 4.4.15.3) and 4.5.x (prior to 4.5.4) are affected.
Solution
Upgrade to phpMyAdmin 4.0.10.13 or newer, 4.4.15.3 or newer, 4.5.4 or newer or apply patch listed below.
References
Thanks to Emanuel Bronshtein @e3amn2l for reporting these vulnerabilities.
Assigned CVE IDs: CVE-2016-2040
Patches
The following commits have been made on the 4.0 branch to fix this issue:
- 9f3488fc3ab6b83618dbb4bebbea4b973764e2ac
- 0ce4fd2750491a54d27f94cc1403f9da21738aa6
- 27eb98faedcdcd0b856577fcbdfe3e87b2445345
The following commits have been made on the 4.4 branch to fix this issue:
- 2b3f915f72bfe7eb9ae60a69582f041ddc55f663
- 75de41635d387e1c3c8d71a746241502a90c8422
- 1414d60cbfe01a2d08ab9d5e6a7178a6323fca68
The following commits have been made on the 4.5 branch to fix this issue:
- 75a55824012406a08c4debf5ddb7ae41c32a7dbc
- edffb52884b09562490081c3b8666ef46c296418
- aca42efa01917cc0fe8cfdb2927a6399ca1742f2
More information
For further information and in case of questions, please contact the phpMyAdmin security team at security@phpmyadmin.net.