The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is used, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via a NUL byte inside a "</script" sequence.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade phpmyadmin | Jul 30, 2024 | Sep 30, 2008 |
| Phpmyadmin | — | Upgrade phpMyAdmin to the latest version | May 4, 2017 | Sep 30, 2008 |
| Suse | — | Upgrade phpmyadmin | Feb 17, 2015 | Sep 30, 2008 |
| Ubuntu | — | Upgrade phpmyadmin | Nov 19, 2024 | Sep 30, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub