PatchSiren cyber security CVE debrief
CVE-2016-6621 Phpmyadmin CVE debrief
CVE-2016-6621 describes a server-side request forgery (SSRF) issue in the phpMyAdmin setup script. NVD lists the flaw as network-exploitable with no privileges or user interaction required, and maps it to CWE-918. Fixed releases are identified as 4.0.10.19, 4.4.15.10, and 4.6.6.
- Vendor
- Phpmyadmin
- Product
- Unknown
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-31
- Advisory updated
- 2026-05-13
Who should care
Administrators running phpMyAdmin should prioritize this, especially if the setup script is reachable from any untrusted network. Security teams should also check for packaged or bundled phpMyAdmin deployments that may lag behind the fixed releases.
Technical summary
The vulnerable component is phpMyAdmin's setup script in releases before 4.0.10.19, 4.4.15.10, and 4.6.6. NVD assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N, indicating a remotely reachable issue that can cause the server to make attacker-influenced requests. The record classifies the weakness as CWE-918.
Defensive priority
High. The issue is remotely reachable, requires no authentication or user interaction, and carries a CVSS score of 8.6. Treat it as a priority remediation item for any exposed phpMyAdmin deployment.
Recommended defensive actions
- Upgrade phpMyAdmin to 4.0.10.19, 4.4.15.10, 4.6.6, or later supported releases.
- Verify that the setup script is not publicly reachable; restrict access to trusted administrative networks only.
- If phpMyAdmin is no longer needed, remove or disable the installation rather than leaving it exposed.
- Review outbound network controls from the web/application tier to reduce the impact of server-initiated requests.
- Check vendor and distro advisories for packaged phpMyAdmin versions and any backported fixes.
Evidence notes
The NVD description states that the phpMyAdmin setup script before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct SSRF via unspecified vectors. NVD maps the weakness to CWE-918 and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The reference set includes the phpMyAdmin vendor advisory, a Debian LTS notice, and a SecurityFocus entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6621 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6621
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6621 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6621
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2018/07/msg00006.html
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.phpmyadmin.net/security/PMASA-2016-44/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.