GHSA-5h5m-fj48-qpjw — phpmyadmin/phpmyadmin
MEDIUMGHSA-5h5m-fj48-qpjw is a medium-severity (CVSS 6.1) Open Redirect vulnerability in phpmyadmin/phpmyadmin. A fix is available for phpmyadmin/phpmyadmin — see the affected versions and patch details below.
phpMyAdmin Open Redirect
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-5h5m-fj48-qpjw by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
phpmyadmin/phpmyadmin🐘phpmyadmin/phpmyadmin🐘phpmyadmin/phpmyadminReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | phpmyadmin/phpmyadmin | ≥ 4.6&&< 4.6.6 | 4.6.6composer require phpmyadmin/phpmyadmin:^4.6.6 |
| 🐘Packagist | phpmyadmin/phpmyadmin | ≥ 4.4&&< 4.4.15.10 | 4.4.15.10composer require phpmyadmin/phpmyadmin:^4.4.15.10 |
| 🐘Packagist | phpmyadmin/phpmyadmin | ≥ 4.0&&< 4.0.10.19 | 4.0.10.19composer require phpmyadmin/phpmyadmin:^4.0.10.19 |
Affected Products
phpmyadminphpmyadminDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for phpmyadmin/phpmyadmin, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update phpmyadmin/phpmyadmin to 4.6.6 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-5h5m-fj48-qpjw is resolved across your whole dependency graph.
Workarounds
Stop reflecting attacker-controlled destinations: resolve every redirect target against an allowlist of paths or hosts you own, prefer a server-side key over a full URL in the request, and reject absolute URLs entirely where the flow only ever needs a relative one.
Frequently Asked Questions
Is GHSA-5h5m-fj48-qpjw in your dependencies?
Find it across Packagist, including transitive dependencies.