ZeroHour

CVE-2016-2041

CVSS 3.0
7.5 high
EPSS
3%p85
Published
()
Modified
Description

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

Vendors
fedoraprojectphpmyadminopensuse
Products
fedora, phpmyadmin, leap, opensuse
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.