An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade phpmyadmin | Sep 12, 2018 | Aug 24, 2018 |
| Freebsd | — | Upgrade phpMyAdmin-php71Upgrade phpMyAdmin-php56Upgrade phpMyAdmin-php70Upgrade phpMyAdmin-php72Upgrade phpMyAdmin | Aug 23, 2018 | Aug 22, 2018 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | Oct 16, 2019 | Aug 24, 2018 |
| Suse | — | Upgrade phpmyadmin | Aug 28, 2018 | Aug 21, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub