PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6621 Phpmyadmin CVE debrief

CVE-2016-6621 describes a server-side request forgery (SSRF) issue in the phpMyAdmin setup script. NVD lists the flaw as network-exploitable with no privileges or user interaction required, and maps it to CWE-918. Fixed releases are identified as 4.0.10.19, 4.4.15.10, and 4.6.6.

Vendor
Phpmyadmin
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

Administrators running phpMyAdmin should prioritize this, especially if the setup script is reachable from any untrusted network. Security teams should also check for packaged or bundled phpMyAdmin deployments that may lag behind the fixed releases.

Technical summary

The vulnerable component is phpMyAdmin's setup script in releases before 4.0.10.19, 4.4.15.10, and 4.6.6. NVD assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N, indicating a remotely reachable issue that can cause the server to make attacker-influenced requests. The record classifies the weakness as CWE-918.

Defensive priority

High. The issue is remotely reachable, requires no authentication or user interaction, and carries a CVSS score of 8.6. Treat it as a priority remediation item for any exposed phpMyAdmin deployment.

Recommended defensive actions

  • Upgrade phpMyAdmin to 4.0.10.19, 4.4.15.10, 4.6.6, or later supported releases.
  • Verify that the setup script is not publicly reachable; restrict access to trusted administrative networks only.
  • If phpMyAdmin is no longer needed, remove or disable the installation rather than leaving it exposed.
  • Review outbound network controls from the web/application tier to reduce the impact of server-initiated requests.
  • Check vendor and distro advisories for packaged phpMyAdmin versions and any backported fixes.

Evidence notes

The NVD description states that the phpMyAdmin setup script before 4.0.10.19, 4.4.x before 4.4.15.10, and 4.6.x before 4.6.6 allows remote attackers to conduct SSRF via unspecified vectors. NVD maps the weakness to CWE-918 and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. The reference set includes the phpMyAdmin vendor advisory, a Debian LTS notice, and a SecurityFocus entry.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6621 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6621

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6621 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6621

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.