Lucene search

K
osvGoogleOSV:GHSA-XPXP-V33M-5JP9
HistoryMay 17, 2022 - 5:16 a.m.

phpMyAdmin Unsafe Fetching of Javascript Code

2022-05-1705:16:32
Google
osv.dev
3
phpmyadmin
javascript
http
session
phpmyadmin.net
ssl
cross-site scripting
attack

EPSS

0.001

Percentile

49.2%

phpMyAdmin 3.5.x before 3.5.3 uses JavaScript code that is obtained through an HTTP session to phpmyadmin.net without SSL, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by modifying this code.