A vulnerability was discovered where a user can be tricked in to following a link leading to phpMyAdmin, which after authentication redirects to another malicious site.
The attacker must sniff the user's valid phpMyAdmin token.
We consider this vulnerability to be of moderate severity.
All 4.0.x versions (prior to 22.214.171.124) are affected
Upgrade to phpMyAdmin 126.96.36.199, or newer or apply patch listed below.
Assigned CVE ids: CVE-2016-4412
CWE ids: CWE-661
The following commits have been made on the 4.0 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.