Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39378
HistoryFeb 22, 2023 - 7:42 a.m.

Cross-site Scripting (XSS)

2023-02-2207:42:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
45
cross-site scripting
phpmyadmin
authenticated user
malicious code
browser
.sql file
drag-and-drop interface
vulnerability

EPSS

0.001

Percentile

23.5%

phpmyadmin/phpmyadmin is vulnerable to Cross-site Scripting (XSS). An authenticated user is able to execute malicious code on a victim’s browser by uploading a specially-crafted .sql file through the drag-and-drop interface.