GHSA-6wfj-2mw7-p5cg

    Dashboard / Vulnerabilities / GHSA-6wfj-2mw7-p5cg

    GHSA-6wfj-2mw7-p5cg

    Published: 14 May 2022Last Modified: 8 Dec 2024
    Aliases:

    Summary: phpMyAdmin micro history Implementation XSS Vulnerability

    Details: Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct a cross-site request forgery (CSRF) attack to create a root account, via a crafted URL, related to js/ajax.js.

    Affected packages

    Package

    Name: phpmyadmin/phpmyadmin

    Purl: pkg:composer/phpmyadmin/phpmyadmin

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 4.0.0
    Fixed -4.0.10.3

    Affected versions

    4.0.0
    4.0.1
    4.0.10
    4.0.10.1
    4.0.10.2
    4.0.2
    4.0.3
    4.0.4
    4.0.4.1
    4.0.4.2
    4.0.5
    4.0.6
    4.0.7
    4.0.8
    4.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6wfj-2mw7-p5cg | CVE-DB