Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2h8m-3jwj-j68m

Опубликовано: 21 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 7.2

Описание

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.

EPSS

Процентиль: 16%
0.00244
Низкий

5.3 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
5 месяцев назад

phpMoAdmin 1.1.5 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the collection parameter. Attackers can send GET requests to moadmin.php with script payloads in the collection parameter during collection creation to execute arbitrary JavaScript in users' browsers.

EPSS

Процентиль: 16%
0.00244
Низкий

5.3 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79