PT-2025-52344 · Unknown · Phpmsadmin

Solonbarroso

·

Published

2025-12-18

·

Updated

2025-12-20

·

CVE-2025-63948

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpMsAdmin version 2.2
Description A SQL Injection issue exists in the database mode.php file. An attacker can execute arbitrary SQL commands via the dbname parameter, potentially leading to information disclosure or database manipulation.
Recommendations Update phpMsAdmin to a newer version that addresses this issue. As a temporary workaround, restrict access to the database mode.php file or carefully sanitize the dbname parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63948

Affected Products

Phpmsadmin