Lucene search

K
githubGitHub Advisory DatabaseGHSA-JQMR-WQGP-8MH2
HistoryMay 17, 2022 - 3:20 a.m.

phpMyAdmin cross-site scripting Vulnerability in Table or Column Names

2022-05-1703:20:58
CWE-79
GitHub Advisory Database
github.com
11
phpmyadmin
xss
vulnerability
table names
column names
4.0.x
4.1.x
4.2.x
ajax
remote authentication

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

51.8%

Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before 4.1.14.2, and 4.2.x before 4.2.6 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) table name or (2) column name that is improperly handled during construction of an AJAX confirmation message.

Affected configurations

Vulners
Node
phpmyadminphpmyadminRange<4.2.6
OR
phpmyadminphpmyadminRange<4.1.14.2
OR
phpmyadminphpmyadminRange<4.0.10.1
VendorProductVersionCPE
phpmyadminphpmyadmin*cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

51.8%