CVE-2016-2562Improper Input Validation in Phpmyadmin

Severity
6.8MEDIUMNVD
EPSS
0.2%
top 54.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 1
Latest updateMay 17

Description

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:NExploitability: 2.2 | Impact: 4.0

Affected Packages4 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.5.5.1-1 (bookworm)
Packagistphpmyadmin/phpmyadmin4.54.5.5.1
Debianphpmyadmin/phpmyadmin< 4:4.5.5.1-1+3
NVDphpmyadmin/phpmyadmin10 versions+9

Patches

🔴Vulnerability Details

3
OSV
phpMyAdmin Improper Input Validation2022-05-17
GHSA
phpMyAdmin Improper Input Validation2022-05-17
OSV
CVE-2016-2562: The checkHTTP function in libraries/Config2016-03-01

📋Vendor Advisories

1
Debian
CVE-2016-2562: phpmyadmin - The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before ...2016

💬Community

4
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [epel-all]2016-03-02
Bugzilla
CVE-2016-2562 phpMyAdmin: man-in-the-middle attack on API call to GitHub (PMASA-2016-13)2016-03-02
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin4: various flaws [epel-5]2016-03-02
Bugzilla
CVE-2016-2559 CVE-2016-2562 phpmyadmin: various flaws [fedora-all]2016-03-02