Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fcww-8wvc-38q9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

phpMyAdmin SQL injection vulnerability

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

Пакеты

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 3.4, < 4.9.5

4.9.5

Наименование

phpmyadmin/phpmyadmin

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.2

5.0.2

EPSS

Процентиль: 88%
0.04306
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-89

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVSS3: 5.4
nvd
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which when retrieved (for instance, through the Browse tab) can trigger the XSS attack.

CVSS3: 5.4
debian
около 5 лет назад

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection v ...

suse-cvrf
около 5 лет назад

Security update for phpMyAdmin

suse-cvrf
больше 4 лет назад

Security update for phpMyAdmin

EPSS

Процентиль: 88%
0.04306
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-89