Description
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-551-1 | phpmyadmin security update |
Debian DSA |
DSA-3627-1 | phpmyadmin security update |
EUVD |
EUVD-2016-6674 | phpMyAdmin vulnerable to Cross-Site Request Forgery |
Github GHSA |
GHSA-2p7v-jm8m-g3qq | phpMyAdmin vulnerable to Cross-Site Request Forgery |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T01:08:00.673Z
Reserved: 2016-06-22T00:00:00.000Z
Link: CVE-2016-5739
No data.
Status : Modified
Published: 2016-07-03T01:59:25.970
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-5739
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA