Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-21815
HistoryMar 15, 2022 - 12:00 a.m.

phpLiteAdmin Cross-Site Scripting Vulnerability (CNVD-2022-21815)

2022-03-1500:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
phpliteadmin
cross-site scripting
vulnerability
cnvd-2022-21815
sqlite
data validation
javascript

EPSS

0.001

Percentile

34.0%

phpLiteAdmin is a web-based SQLite database management tool. phpLiteAdmin versions prior to 1.9.8.2 are vulnerable to cross-site scripting. The vulnerability stems from a newRows parameter in index.php that lacks a data validation filter for user-supplied data and output. An attacker could use this vulnerability to execute JavaScript code on the client side.