{"api_version":"1","generated_at":"2026-07-23T12:51:00+00:00","cve":"CVE-2014-125094","urls":{"html":"https://cve.report/CVE-2014-125094","api":"https://cve.report/api/cve/CVE-2014-125094.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-125094","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-125094"},"summary":{"title":"CVE-2014-125094","description":"A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.140405 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-225001 was assigned to this vulnerability.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-04-06 21:15:00","updated_at":"2023-11-07 02:18:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://vuldb.com/?ctiid.225001","name":"https://vuldb.com/?ctiid.225001","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://github.com/osalabs/phpminiadmin/blob/master/changelog.md","name":"https://github.com/osalabs/phpminiadmin/blob/master/changelog.md","refsource":"MISC","tags":[],"title":"phpminiadmin/changelog.md at master · osalabs/phpminiadmin · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.225001","name":"https://vuldb.com/?id.225001","refsource":"MISC","tags":[],"title":"CVE-2014-125094 | phpMiniAdmin cross site scripting","mime":"text/html","httpstatus":"401","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-125094","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-125094","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"125094","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpminiadmin_project","cpe5":"phpminiadmin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2014-125094","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability classified as problematic was found in phpMiniAdmin up to 1.8.120510. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 1.9.140405 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-225001 was assigned to this vulnerability."},{"lang":"deu","value":"In phpMiniAdmin bis 1.8.120510 wurde eine problematische Schwachstelle entdeckt. Das betrifft eine unbekannte Funktionalität. Durch das Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Ein Aktualisieren auf die Version 1.9.140405 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-79 Cross Site Scripting","cweId":"CWE-79"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"phpMiniAdmin","version":{"version_data":[{"version_affected":"=","version_value":"1.8.120510"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.225001","refsource":"MISC","name":"https://vuldb.com/?id.225001"},{"url":"https://vuldb.com/?ctiid.225001","refsource":"MISC","name":"https://vuldb.com/?ctiid.225001"},{"url":"https://github.com/osalabs/phpminiadmin/blob/master/changelog.md","refsource":"MISC","name":"https://github.com/osalabs/phpminiadmin/blob/master/changelog.md"}]},"impact":{"cvss":[{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"},{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}]}},"nvd":{"publishedDate":"2023-04-06 21:15:00","lastModifiedDate":"2023-11-07 02:18:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:phpminiadmin_project:phpminiadmin:*:*:*:*:*:*:*:*","versionEndExcluding":"1.9.140405","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}