PT-2018-11267 · Phpmyadmin+4 · Phpmyadmin+4

William Desportes

·

Published

2018-06-21

·

Updated

2024-06-15

·

CVE-2018-12581

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMyAdmin versions prior to 4.8.2
Description A Cross-Site Scripting issue has been found where an attacker can use a crafted database name to trigger an attack when that database is referenced from the Designer feature. The issue is related to the js/designer/move.js file.
Recommendations For versions prior to 4.8.2, update to version 4.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Designer feature until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1925
CVE-2018-12581
GHSA-VXJ6-PM6R-23HQ
MGASA-2018-0304
OPENSUSE-SU-2018_1806-1
OPENSUSE-SU-2024:11171-1
USN-4843-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Phpmyadmin