In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade phpmyadmin | Aug 22, 2024 | Mar 22, 2020 |
| Debian | — | Upgrade phpmyadmin | Mar 24, 2020 | Mar 22, 2020 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | Mar 25, 2020 | Mar 22, 2020 |
| Suse | — | Upgrade phpmyadmin | Mar 31, 2020 | Mar 22, 2020 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 20, 2020 | Mar 22, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub