Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php
Published Aug 22, 2014
3.5
LOWCVSS 2.0
EPSS 1.71%
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.
Affected products
No data.
Configuration 1
- 4.0.0
- 4.0.0
- 4.0.0
- 4.0.1
- 4.0.2
- 4.0.3
- 4.0.4
- 4.0.4.1
- 4.0.4.2
- 4.0.5
- 4.0.6
- 4.0.7
- 4.0.8
- 4.0.9
- 4.0.10
- 4.0.10.1
Configuration 2
- 4.1.0
- 4.1.1
- 4.1.2
- 4.1.3
- 4.1.4
- 4.1.5
- 4.1.6
- 4.1.7
- 4.1.8
- 4.1.9
- 4.1.10
- 4.1.11
- 4.1.12
- 4.1.13
- 4.1.14
- 4.1.14.1
- 4.1.14.2
Configuration 3
- 4.2.0
- 4.2.1
- 4.2.2
- 4.2.3
- 4.2.4
- 4.2.5
- 4.2.6
- 4.2.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.71% (0.01706) | 76.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.71% (0.01706) | 74.23th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.33% (0.00326) | 53.28th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00147) | 52.15th | v3 (v2023.03.01) |
| Apr 3, 2024 | 0.15% (0.00150) | 50.41th | v3 (v2023.03.01) |
| Jul 29, 2023 | 0.14% (0.00145) | 49.60th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.14% (0.00139) | 47.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.31% (0.01315) | 68.50th | v2 (v2022.01.01) |
| Feb 22, 2023 | 1.31% (0.01315) | 68.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.31% (0.01315) | 66.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.31% (0.01315) | 41.88th | v2 (v2022.01.01) |
References (8)
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00045.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/60397 third-party-advisoryx_refsource_SECUNIA
- http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php x_refsource_CONFIRMVendor Advisory
- https://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614 x_refsource_CONFIRMExploitPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821 x_refsource_CONFIRMExploitPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccb x_refsource_CONFIRMExploitPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cb x_refsource_CONFIRMExploitPatch
- https://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c x_refsource_CONFIRMExploitPatch
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-updates/2014-08/msg00045.html | vendor-advisoryx_refsource_SUSE | |
| http://secunia.com/advisories/60397 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.phpmyadmin.net/home_page/security/PMASA-2014-8.php | x_refsource_CONFIRMVendor Advisory | |
| https://github.com/phpmyadmin/phpmyadmin/commit/2c45d7caa614afd71dbe3d0f7270f51ce5569614 | x_refsource_CONFIRMExploitPatch | |
| https://github.com/phpmyadmin/phpmyadmin/commit/3ffc967fb60cf2910cc2f571017e977558c67821 | x_refsource_CONFIRMExploitPatch | |
| https://github.com/phpmyadmin/phpmyadmin/commit/647c9d12e33a6b64e1c3ff7487f72696bdf2dccb | x_refsource_CONFIRMExploitPatch | |
| https://github.com/phpmyadmin/phpmyadmin/commit/90ddeecf60fc029608b972e490b735f3a65ed0cb | x_refsource_CONFIRMExploitPatch | |
| https://github.com/phpmyadmin/phpmyadmin/commit/cd9f302bf7f91a160fe7080f9a612019ef847f1c | x_refsource_CONFIRMExploitPatch |
Change history (0)
No recorded changes yet.