CVE-2014-1879Cross-site Scripting in Phpmyadmin

Severity
3.5LOWNVD
EPSS
0.2%
top 57.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 20
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1.7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename in an import action.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages3 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.1.7-1 (bookworm)
Debianphpmyadmin/phpmyadmin< 4:4.1.7-1+3
NVDphpmyadmin/phpmyadmin4.1.6+128

🔴Vulnerability Details

2
GHSA
GHSA-6m6g-jfj8-2gh7: Cross-site scripting (XSS) vulnerability in import2022-05-17
OSV
CVE-2014-1879: Cross-site scripting (XSS) vulnerability in import2014-02-20

📋Vendor Advisories

1
Debian
CVE-2014-1879: phpmyadmin - Cross-site scripting (XSS) vulnerability in import.php in phpMyAdmin before 4.1....2014

💬Community

4
Bugzilla
CVE-2014-1879 phpMyAdmin: XSS in import.php [fedora-all]2014-02-20
Bugzilla
CVE-2014-1879 phpMyAdmin: XSS in import.php [epel-6]2014-02-20
Bugzilla
CVE-2014-1879 phpMyAdmin: XSS in import.php2014-02-20
Bugzilla
CVE-2014-1879 phpMyAdmin3: phpMyAdmin: XSS in import.php [epel-5]2014-02-20