Lucene search

K
githubGitHub Advisory DatabaseGHSA-6HR3-44GX-G6WH
HistoryFeb 13, 2023 - 6:30 a.m.

Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin

2023-02-1306:30:59
CWE-79
GitHub Advisory Database
github.com
32
phpmyadmin
cross-site scripting
drag-and-drop
vulnerability
xss
upload
configuration
directive
authentication
protection

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.5%

In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger Cross-site Scripting (XSS) by uploading a crafted .sql file through the drag-and-drop interface. By disabling the configuration directive $cfg['enable_drag_drop_import'], users will be unable to use the drag and drop upload which would protect against the vulnerability.

Affected configurations

Vulners
Node
phpmyadminphpmyadminRange5.05.2.1
OR
phpmyadminphpmyadminRange4.3.04.9.11
VendorProductVersionCPE
phpmyadminphpmyadmin*cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.5%