QID 730340

Date Published: 2022-02-07

QID 730340: PhpMyAdmin Cross-Site Scripting (XSS) Vulnerability (PMASA-2022-2)

PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.

CVE-2022-23808: An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.

Affected Versions:
phpMyAdmin versions from 5.1.x prior to 5.1.2.

QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary javascripts on the target system.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Users are advised to upgrade to phpMyAdmin 5.1.2 or the latest version.
    Vendor References

    CVEs related to QID 730340

    Software Advisories
    Advisory ID Software Component Link
    PMASA-2022-2 URL Logo www.phpmyadmin.net/security/PMASA-2022-2/