ZeroHour

CVE-2016-2039

CVSS 3.0
5.3 medium
EPSS
2%p84
Published
()
Modified
Description

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

Vendors
opensusephpmyadminfedoraproject
Products
leap, opensuse, phpmyadmin, fedora
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.