QID 996703
Date Published: 2024-01-16
QID 996703: PHP (Composer) Security Update for phpmyadmin/phpmyadmin (GHSA-xhqq-554j-p4x8)
Multiple directory traversal vulnerabilities in the relational schema implementation in phpMyAdmin 3.4.x before 3.4.3.2 allow remote authenticated users to include and execute arbitrary local files via directory traversal sequences in an export type field, related to (1) libraries/schema/User_Schema.class.php and (2) schema_export.php.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xhqq-554j-p4x8 for updates and patch information.
Vendor References
- GHSA-xhqq-554j-p4x8 -
github.com/advisories/GHSA-xhqq-554j-p4x8
CVEs related to QID 996703
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xhqq-554j-p4x8 | phpmyadmin/phpmyadmin |
|