CVE-2025-24529
- EPSS 0.07%
- Veröffentlicht 23.01.2025 06:15:27
- Zuletzt bearbeitet 23.01.2025 06:15:27
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the Insert tab.
CVE-2025-24530
- EPSS 0.07%
- Veröffentlicht 23.01.2025 06:15:27
- Zuletzt bearbeitet 23.01.2025 06:15:27
An issue was discovered in phpMyAdmin 5.x before 5.2.2. An XSS vulnerability has been discovered for the check tables feature. A crafted table or database name could be used for XSS.
CVE-2023-25727
- EPSS 8.03%
- Veröffentlicht 13.02.2023 06:15:11
- Zuletzt bearbeitet 21.03.2025 15:15:41
In phpMyAdmin before 4.9.11 and 5.x before 5.2.1, an authenticated user can trigger XSS by uploading a crafted .sql file through the drag-and-drop interface.
CVE-2020-22452
- EPSS 1.55%
- Veröffentlicht 26.01.2023 21:15:21
- Zuletzt bearbeitet 01.04.2025 15:15:49
SQL Injection vulnerability in function getTableCreationQuery in CreateAddField.php in phpMyAdmin 5.x before 5.2.0 via the tbl_storage_engine or tbl_collation parameters to tbl_create.php.
CVE-2022-0813
- EPSS 0.42%
- Veröffentlicht 10.03.2022 17:44:57
- Zuletzt bearbeitet 21.11.2024 06:39:26
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
CVE-2022-23807
- EPSS 0.07%
- Veröffentlicht 22.01.2022 02:15:07
- Zuletzt bearbeitet 21.11.2024 06:49:17
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
CVE-2022-23808
- EPSS 68.84%
- Veröffentlicht 22.01.2022 02:15:07
- Zuletzt bearbeitet 05.05.2025 17:17:58
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
CVE-2020-22278
- EPSS 0.41%
- Veröffentlicht 04.11.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:13:13
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
CVE-2020-26934
- EPSS 2.79%
- Veröffentlicht 10.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:32
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
CVE-2020-26935
- EPSS 80.07%
- Veröffentlicht 10.10.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:32
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker could use this flaw to inject mali...