Lucene search

K
osvGoogleOSV:GHSA-6WFJ-2MW7-P5CG
HistoryMay 14, 2022 - 2:09 a.m.

phpMyAdmin micro history Implementation XSS Vulnerability

2022-05-1402:09:44
Google
osv.dev
16
xss vulnerability
micro history implementation
phpmyadmin
remote attackers
web script
html
csrf attack
crafted url
js/ajax.js

EPSS

0.002

Percentile

60.9%

Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.