CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
59.0%
Announcement-ID: PMASA-2018-1
Date: 2018-02-20
Self XSS in central columns feature
A self-cross site scripting (XSS) vulnerability has been reported relating to the central columns feature.
We consider this vulnerability to be of moderate severity.
A valid token must be used in the attack
Versions 4.7.x (prior to 4.7.8) are affected. Versions since 4.3.0 are also affected, but they are no longer supported.
Upgrade to phpMyAdmin 4.7.8 or newer or apply patch listed below.
Thanks to Mayur Udiniya for finding this vulnerability. His blog post about the vulnerability, https://udiniya.wordpress.com/2018/02/21/a-tale-of-stealing-session-cookie-in-phpmyadmin
Assigned CVE ids: CVE-2018-7260
CWE ids: CWE-661
The following commits have been made on the 4.7 branch to fix this issue:
For further information and in case of questions, please contact the phpMyAdmin team. Our website is phpmyadmin.net.
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
SINGLE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
Percentile
59.0%