Announcement-ID: PMASA-2016-25
Date: 2016-06-23
XSS in partition range functionality
A vulnerability was reported allowing a specially crafted table parameters to cause an XSS attack through the table structure page.
We consider this vulnerability to be severe.
All 4.6.x versions (prior to 4.6.3) are affected
Upgrade to phpMyAdmin 4.6.3 or newer or apply patch listed below.
Thanks to Emanuel Bronshtein @e3amn2l and Nils Juenemann @totally_unknown for reporting these vulnerabilities.
Assigned CVE ids: CVE-2016-5732
CWE ids: CWE-661
The following commits have been made on the 4.6 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.