Lucene search

K
githubGitHub Advisory DatabaseGHSA-XPXP-V33M-5JP9
HistoryMay 17, 2022 - 5:16 a.m.

phpMyAdmin Unsafe Fetching of Javascript Code

2022-05-1705:16:32
CWE-79
GitHub Advisory Database
github.com
11
phpmyadmin
javascript
http
session
ssl
cross-site scripting
xss
attacks

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.2%

phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.

Affected configurations

Vulners
Node
phpmyadminphpmyadminRange3.53.5.3
VendorProductVersionCPE
phpmyadminphpmyadmin*cpe:2.3:a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.2%