XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack); the "Tracking" feature (a specially-crafted query can be used to trigger an XSS attack); and GIS visualization feature. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade phpmyadmin | Aug 30, 2017 | Dec 11, 2016 |
| Debian | — | Upgrade phpmyadmin | Feb 20, 2019 | Dec 10, 2016 |
| Freebsd | — | Upgrade phpMyAdmin | Dec 10, 2025 | Aug 17, 2016 |
| Gentoo Linux | — | Upgrade dev-db/phpmyadmin. | Oct 30, 2017 | Dec 10, 2016 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Dec 11, 2016 |
| Suse | — | Upgrade phpmyadmin | Nov 3, 2016 | Aug 29, 2016 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub