VDB

DEBIAN-CVE-2015-3902

DEBIAN-CVE-2015-3902 PUBLISHED CVSS 4.599999904632568 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in the setup process in phpMyAdmin 4.0.x before 4.0.10.10, 4.2.x before 4.2.13.3, 4.3.x before 4.3.13.1, and 4.4.x before 4.4.6.1 allow remote attackers to hijack the authentication of administrators for requests that modify the configuration file.

Risk Scores

CVSS 4.0
4.599999904632568
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:12phpmyadmin0, 0, 0
Debian:14phpmyadmin0
Debian:13phpmyadmin0, 0, 0
Debian:11phpmyadmin0, 0, 0

Timeline

  • May 26, 2015 CVE Published
  • May 7, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›