phpMyAdmin Vulnerable to Cross-Site Scripting
Low severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 12, 2025
Package
Affected versions
>= 3.3.0, < 3.3.10.1
>= 3.4.0, < 3.4.1
Patched versions
3.3.10.1
3.4.1
Description
Published by the National Vulnerability Database
Jan 26, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 12, 2025
Last updated
Apr 12, 2025
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page, related to (1) libraries/tbl_links.inc.php and (2) tbl_tracking.php.
References