PT-2022-12910 · Unknown+2 · Phpliteadmin+2

Published

2022-03-13

·

Updated

2022-08-08

·

CVE-2021-46709

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpLiteAdmin versions prior to 1.9.8.2
Description The issue allows for XSS attacks via the newRows parameter, also known as num or number, in the index.php file.
Recommendations For versions prior to 1.9.8.2, avoid using the newRows parameter in the index.php file until a fix is available. As a temporary workaround, consider restricting access to the index.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-46709
USN-5552-1

Affected Products

Linuxmint
Ubuntu
Phpliteadmin