PHPMemcachedAdmin vulnerable to cross-site scripting (XSS) via improper encoding
Moderate severity
GitHub Reviewed
Published
Nov 30, 2023
to the GitHub Advisory Database
•
Updated Dec 18, 2023
Description
Published by the National Vulnerability Database
Nov 30, 2023
Published to the GitHub Advisory Database
Nov 30, 2023
Reviewed
Dec 6, 2023
Last updated
Dec 18, 2023
A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.
References