CVE-2018-15605Cross-site Scripting in Phpmyadmin

Severity
6.1MEDIUMNVD
EPSS
0.7%
top 28.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 24
Latest updateMay 14

Description

An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulnerability has been found where an attacker can use a crafted file to manipulate an authenticated user who loads that file through the import feature.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

Packagistphpmyadmin/phpmyadmin< 4.8.3

Patches

🔴Vulnerability Details

2
GHSA
phpMyAdmin Cross-site Scripting (XSS) in the import dialog2022-05-14
OSV
phpMyAdmin Cross-site Scripting (XSS) in the import dialog2022-05-14

📋Vendor Advisories

1
Debian
CVE-2018-15605: phpmyadmin - An issue was discovered in phpMyAdmin before 4.8.3. A Cross-Site Scripting vulne...2018

💬Community

1
Bugzilla
CVE-2018-15605 phpMyAdmin: XSS in the import dialog2018-08-22