Lucene search

K
githubGitHub Advisory DatabaseGHSA-5P69-RMX8-7GW7
HistoryMay 17, 2022 - 4:19 a.m.

phpMyAdmin Multiple XSS Vulnerabilities

2022-05-1704:19:07
CWE-79
GitHub Advisory Database
github.com
3
phpmyadmin
xss
vulnerabilities
pma_uninlineeditrow
remote users
web script
html
database name
table name
column name
inline editing

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

49.5%

Multiple cross-site scripting (XSS) vulnerabilities in the PMA_unInlineEditRow function in js/sql.js in phpMyAdmin 3.4.x before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via a (1) database name, (2) table name, or (3) column name that is not properly handled after an inline-editing operation.

Affected configurations

Vulners
Node
phpmyadminphpmyadminRange3.4.03.4.5
VendorProductVersionCPE
phpmyadminphpmyadmin*cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.6

Confidence

High

EPSS

0.001

Percentile

49.5%