CVE-2023-25727
published 2023-02-13CVE-2023-25727: In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.16%
63.7th percentile
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | phpmyadmin | < phpmyadmin 4:5.2.1+dfsg-1 (bookworm) | phpmyadmin 4:5.2.1+dfsg-1 (bookworm) |
| phpmyadmin | phpmyadmin | < 4.9.11 | 4.9.11 |
| phpmyadmin | phpmyadmin | >= 0 < 4:5.0.4+dfsg2-2+deb11u2 | 4:5.0.4+dfsg2-2+deb11u2 |
| phpmyadmin | phpmyadmin | >= 0 < 4:5.2.1+dfsg-1 | 4:5.2.1+dfsg-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:5.2.1+dfsg-1 | 4:5.2.1+dfsg-1 |
| phpmyadmin | phpmyadmin | >= 0 < 4:5.2.1+dfsg-1 | 4:5.2.1+dfsg-1 |
| phpmyadmin | phpmyadmin | >= 4.3.0 < 4.9.11 | 4.9.11 |
| phpmyadmin | phpmyadmin | >= 5.0 < 5.2.1 | 5.2.1 |
| phpmyadmin | phpmyadmin | >= 5.0.0 < 5.2.1 | 5.2.1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
osv·2023-02-13
CVE-2023-25727 [MEDIUM] Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger Cross-site Scripting (XSS) by uploading a crafted .sql file through the drag-and-drop interface. By disabling the configuration directive `$cfg['enable_drag_drop_import']`, users will be unable to use the drag and drop upload which would protect against the vulnerability.
GHSA
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
ghsa·2023-02-13
CVE-2023-25727 [MEDIUM] CWE-79 Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger Cross-site Scripting (XSS) by uploading a crafted .sql file through the drag-and-drop interface. By disabling the configuration directive `$cfg['enable_drag_drop_import']`, users will be unable to use the drag and drop upload which would protect against the vulnerability.
OSV
CVE-2023-25727: In phpMyAdmin before 4
osv·2023-02-13·CVSS 5.4
CVE-2023-25727 [MEDIUM] CVE-2023-25727: In phpMyAdmin before 4
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Debian
CVE-2023-25727: phpmyadmin - In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trig...
vendor_debian·2023·CVSS 5.4
CVE-2023-25727 [MEDIUM] CVE-2023-25727: phpmyadmin - In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trig...
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Scope: local
bookworm: resolved (fixed in 4:5.2.1+dfsg-1)
bullseye: resolved (fixed in 4:5.0.4+dfsg2-2+deb11u2)
forky: resolved (fixed in 4:5.2.1+dfsg-1)
sid: resolved (fixed in 4:5.2.1+dfsg-1)
trixie: resolved (fixed in 4:5.2.1+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-13
Published