Logo
vulnerabilityCVE-2023-25727
Name
CVE-2023-25727
Source
NVD ( link)Debian ( link)
Description
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
phpmyadmin
Patched

Vulnerability Ratings#


5.4
CVSSv31
5.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
5.2.3
Not Affected
yocto
scarthgap
5.2.2
Not Affected

Resolved with patches#


phpmyadmin (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix not escaped title when using drag and drop upload
=?UTF-8?q?Maur=C3=ADcio=20Meneghini=20Fauth?= <mauricio@fauth.dev>
CVE-2023-25727