CVE-2017-1000016: phpMyAdmin

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.

Affected products

  • phpMyAdmin phpMyAdmin: version 4.6.0 only; version 4.6.1 only; version 4.6.2 only; version 4.6.3 only; version 4.6.4 only; version 4.6.5 only; …

Published 2017-07-17. Last modified 2026-06-17.