QID 730340
Date Published: 2022-02-07
QID 730340: PhpMyAdmin Cross-Site Scripting (XSS) Vulnerability (PMASA-2022-2)
PhpMyAdmin is a free software tool written in PHP and intended to handle the administration of MySQL over the Internet.
CVE-2022-23808: An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
Affected Versions:
phpMyAdmin versions from 5.1.x prior to 5.1.2.
QID Detection Logic (unauthenticated):
Look for vulnerable version of phpmyadmin installed.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary javascripts on the target system.
Solution
Users are advised to upgrade to phpMyAdmin 5.1.2 or the latest version.
Vendor References
- PMASA-2022-2 -
www.phpmyadmin.net/security/PMASA-2022-2/
CVEs related to QID 730340
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| PMASA-2022-2 |
|