CVE-2014-5274Cross-site Scripting in Phpmyadmin

Severity
3.5LOWNVD
EPSS
0.2%
top 55.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages5 packages

debiandebian/phpmyadmin< phpmyadmin 4:4.2.7.1-1 (bookworm)
Packagistphpmyadmin/phpmyadmin4.1.04.1.14.3+1
Debianphpmyadmin/phpmyadmin< 4:4.2.7.1-1+3
NVDphpmyadmin/phpmyadmin25 versions+24
NVDopensuse/opensuse13.1, 13.2+1

Patches

🔴Vulnerability Details

3
OSV
phpMyAdmin cross-site scripting vulnerability in crafted view name2022-05-14
GHSA
phpMyAdmin cross-site scripting vulnerability in crafted view name2022-05-14
OSV
CVE-2014-5274: Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 42014-08-22

📋Vendor Advisories

1
Debian
CVE-2014-5274: phpmyadmin - Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdm...2014

💬Community

3
Bugzilla
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [fedora-all]2014-08-18
Bugzilla
CVE-2014-5274 phpMyAdmin: cross-site scripting flaw on view operations page (PMASA-2014-9)2014-08-18
Bugzilla
CVE-2014-5274 CVE-2014-5273 phpMyAdmin: various flaws [epel-7]2014-08-18