Back

LOW

phpMyAdmin: Self-XSS due to unescaped HTML output in recent/favorite tables navigation

Published Jun 25, 2014

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of phpMyAdmin as shipped with any Red Hat product.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 25, 2014
Updated Aug 6, 2024
Reserved Jun 20, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 20, 2014