Back

LOW

phpMyAdmin: Self-XSS due to unescaped HTML output in navigation items hiding feature

Published Jun 25, 2014

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of phpMyAdmin as shipped with any Red Hat product.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 25, 2014
Updated Aug 6, 2024
Reserved Jun 20, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 20, 2014
ENISA EUVD
Assigner mitre
Published Jun 25, 2014
Updated Aug 6, 2024
Exploited since n/a
EUVD-2014-4276