Lucene search

K
githubGitHub Advisory DatabaseGHSA-WV8G-FX9J-Q2JG
HistoryMay 17, 2022 - 3:57 a.m.

phpMyAdmin cross-site scripting Vulnerability via ENUM value

2022-05-1703:57:46
CWE-79
GitHub Advisory Database
github.com
8
phpmyadmin
xss
enum value
table search
table structure
remote authenticated users
injection
arbitrary web script
html
libraries
tablesearch.class.php
util.class.php

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly handled during rendering of the (1) table search or (2) table structure page, related to libraries/TableSearch.class.php and libraries/Util.class.php.

Affected configurations

Vulners
Node
phpmyadminphpmyadminRange4.2.04.2.9.1
OR
phpmyadminphpmyadminRange4.1.04.1.14.5
OR
phpmyadminphpmyadminRange4.0.04.0.10.4
VendorProductVersionCPE
phpmyadminphpmyadmin*cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%