CVE-2016-5739: Opensuse Leap
High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, which makes it easier for remote attackers to conduct CSRF attacks by reading an authentication token in a Referer header, related to libraries/Header.php.
Affected products
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- phpMyAdmin phpMyAdmin: version 4.4.0 only; version 4.4.1 only; version 4.4.1.1 only; version 4.4.2 only; version 4.4.3 only; version 4.4.4 only; …
Published 2016-07-03. Last modified 2026-06-17.