PT-2025-47581 · Unknown · Phppgadmin
Published
2025-11-17
·
Updated
2025-11-21
·
CVE-2025-60796
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpPgAdmin versions prior to 7.13.0
Description
The software contains multiple cross-site scripting (XSS) issues across various components. User-supplied input from
$ REQUEST parameters is reflected in HTML output without proper encoding or sanitization. Specifically, the issue is present in files including sequences.php, indexes.php, and admin.php. An attacker can exploit these issues to execute arbitrary JavaScript in a victim’s browser, potentially leading to session hijacking or credential theft.Recommendations
Update to a version newer than 7.13.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phppgadmin