Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33828
HistoryJan 23, 2022 - 5:39 p.m.

Cross-Site Scripting (XSS)

2022-01-2317:39:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
phpmyadmin
cross-site scripting
vulnerability
escape
config-form
action attribute
setup script
html injection

EPSS

0.013

Percentile

86.2%

phpmyadmin is vulnerable to cross-site scripting. The vulnerability exists due to a lack of escape of the config-form’s action attribute. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.