ZeroHour

CVE-2016-4412

CVSS 3.0
4.4 medium
EPSS
1%p61
Published
()
Modified
Description

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.

Vendors
phpmyadmin
Products
phpmyadmin
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.