phpMyAdmin vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Package
Affected versions
>= 4.4.0, < 4.4.15.7
>= 4.6.0, < 4.6.3
Patched versions
4.4.15.7
4.6.3
Description
Published by the National Vulnerability Database
Jul 3, 2016
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Apr 14, 2025
Last updated
Apr 14, 2025
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.7 and 4.6.x before 4.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) server-privileges certificate data fields on the user privileges page, (2) an "invalid JSON" error message in the error console, (3) a database name in the central columns implementation, (4) a group name, or (5) a search name in the bookmarks implementation.
References